Vendor CVEs
Xenforo
All CVEs
30 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-71279 | Cri | 0.64 | 9.8 | 0.00 | Apr 1, 2026 | XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication. | ||
| CVE-2024-38457 | Hig | 0.58 | 8.8 | 0.07 | Jun 16, 2024 | Xenforo before 2.2.16 allows CSRF. | ||
| CVE-2025-71281 | Hig | 0.57 | 8.8 | 0.00 | Apr 1, 2026 | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method… | ||
| CVE-2025-71278 | Hig | 0.57 | 8.8 | 0.00 | Apr 1, 2026 | XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level. | ||
| CVE-2024-38458 | Hig | 0.57 | 8.8 | 0.01 | Jun 16, 2024 | Xenforo before 2.2.16 allows code injection. | ||
| CVE-2026-73315 | Hig | 0.56 | 8.6 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook… | ||
| CVE-2024-25006 | Hig | 0.53 | 8.1 | 0.01 | Feb 29, 2024 | XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import. | ||
| CVE-2026-73316 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to… | ||
| CVE-2026-73314 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm… | ||
| CVE-2025-71282 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2026 | XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure. | ||
| CVE-2026-73312 | Hig | 0.48 | 7.4 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token… | ||
| CVE-2026-73311 | Hig | 0.48 | 7.4 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed… | ||
| CVE-2026-73309 | Hig | 0.48 | 7.4 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy… | ||
| CVE-2026-74239 | Hig | 0.47 | 7.2 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using… | ||
| CVE-2026-35056 | Hig | 0.47 | 7.2 | 0.01 | Apr 1, 2026 | XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server. | ||
| CVE-2026-73313 | Med | 0.44 | 6.8 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The… | ||
| CVE-2026-73321 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient… | ||
| CVE-2026-35057 | Med | 0.42 | 6.4 | 0.00 | Apr 1, 2026 | XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other… | ||
| CVE-2026-35054 | Med | 0.42 | 6.4 | 0.00 | Apr 1, 2026 | XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content. | ||
| CVE-2024-58342 | Med | 0.41 | 6.3 | 0.00 | Apr 1, 2026 | XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user… | ||
| CVE-2026-73320 | Med | 0.40 | 6.1 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict… | ||
| CVE-2026-73319 | Med | 0.40 | 6.1 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can… | ||
| CVE-2026-35055 | Med | 0.40 | 6.1 | 0.00 | Apr 1, 2026 | XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox. | ||
| CVE-2025-71280 | Med | 0.40 | 6.2 | 0.00 | Apr 1, 2026 | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users. | ||
| CVE-2026-73310 | Med | 0.38 | 5.9 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can… | ||
| CVE-2021-43032 | Med | 0.31 | 4.8 | 0.01 | Nov 3, 2021 | In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side. | ||
| CVE-2023-53904 | Med | 0.30 | 4.6 | 0.00 | Dec 17, 2025 | Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin… | ||
| CVE-2026-73318 | Low | 0.25 | 3.8 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in… | ||
| CVE-2026-73317 | Low | 0.18 | 2.7 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID… | ||
| CVE-2026-51833 | Hig | 0.00 | 7.5 | 0.00 | Jul 17, 2026 | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server. |
- risk 0.64cvss 9.8epss 0.00
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
- risk 0.58cvss 8.8epss 0.07
Xenforo before 2.2.16 allows CSRF.
- risk 0.57cvss 8.8epss 0.00
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method…
- risk 0.57cvss 8.8epss 0.00
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.
- risk 0.57cvss 8.8epss 0.01
Xenforo before 2.2.16 allows code injection.
- risk 0.56cvss 8.6epss 0.00
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook…
- risk 0.53cvss 8.1epss 0.01
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
- risk 0.49cvss 7.5epss 0.00
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to…
- risk 0.49cvss 7.5epss 0.01
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm…
- risk 0.49cvss 7.5epss 0.00
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
- risk 0.48cvss 7.4epss 0.00
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token…
- risk 0.48cvss 7.4epss 0.01
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed…
- risk 0.48cvss 7.4epss 0.01
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy…
- risk 0.47cvss 7.2epss 0.01
XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using…
- risk 0.47cvss 7.2epss 0.01
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
- risk 0.44cvss 6.8epss 0.01
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The…
- risk 0.42cvss 6.5epss 0.01
XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient…
- risk 0.42cvss 6.4epss 0.00
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other…
- risk 0.42cvss 6.4epss 0.00
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
- risk 0.41cvss 6.3epss 0.00
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user…
- risk 0.40cvss 6.1epss 0.00
XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict…
- risk 0.40cvss 6.1epss 0.00
XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can…
- risk 0.40cvss 6.1epss 0.00
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
- risk 0.40cvss 6.2epss 0.00
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
- risk 0.38cvss 5.9epss 0.00
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can…
- risk 0.31cvss 4.8epss 0.01
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.
- risk 0.30cvss 4.6epss 0.00
Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin…
- risk 0.25cvss 3.8epss 0.00
XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in…
- risk 0.18cvss 2.7epss 0.00
XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID…
- risk 0.00cvss 7.5epss 0.00
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.