Looks like Lemmy code has a security vulnerability, persistent XSS, that allows injection of Javascript into the sidebar and comments. That allowed the attacker to force load NSFW content even after lemmy.world admins cleaned up the first attack.
Looks like the injected JS code also steals login tokens from your browser, seems some admin accounts got compromised this way.
Probably a good idea to not visit Lemmy sites for time being (or block execution of Javascript in your browser, which is always a good idea).
Issue 1895 opened and patch purposed for the core issue. The markdown editor does no escaping input on custom emojis. This is likely why users on app were seeing text and not getting the redirect.
No. The existing Lemmy-Lite that was advertised on join-Lemmy.org appears to be massively out of date, and no longer actively maintained.
It was a bug with Lemmy-UI, so you might be able to get away using an app or site that isn't vulnerable. Whether that is Wefwef, one of the apps, like Jerboa, or something that is Federated, but not Lemmy, like Kbin, or Mastodon (things might be a bit clunky if you do, since Lemmy threads aren't well handled by Mastodon).