XenForo 2.2.18 Released
Today we are releasing XenForo 2.2.18 to address some potential security vulnerabilities that were recently reported to us. This version only includes security fixes.It is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.3 upgrade to this release to benefit from increased stability.
The issues identified are as follows:
- Prevention of a possible XSS exploit related to lightbox usage in posts (thank you UwU)
- Prevention of a possible RCE (remote code execution) exploit via authenticated, but malicious, admin users (thank you UwU)