- Affected version
- Up until current one
Some bullet points that hopefully explain the issue:
- One of the most visited pages of a XenForo installation might be the What's New page.
- The Latest Profile Posts section allows use of BB Codes.
- Admins and moderators who find themselves downloading a lot of resources (to make sure the community guidelines are being followed) usually enable a profile setting so that they do NOT automatically subscribe to / follow a resource upon download.
- Image proxying doesn't work on same domain so the URL is loaded as is. The[IMG] tag runs the /download GET request successfully.
- Lazy loading helps somehow with the issue, preventing the download until the IMG appears ini the visible viewport.