Known Vulnerabilities for products from XenForo
Listed below are 20 of the newest known vulnerabilities associated with the vendor "XenForo".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-74239 json | Not Provided | 2026-09-08 | 2026-09-09 | |
| CVE-2026-73321 json | Not Provided | 2026-09-08 | 2026-09-10 | |
| CVE-2026-73320 json | XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers ... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73319 json | XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticat... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73318 json | XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP ad... | Not Provided | 2026-09-08 | 2026-09-14 |
| CVE-2026-73317 json | Not Provided | 2026-09-08 | 2026-09-09 | |
| CVE-2026-73316 json | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to pr... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73315 json | XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows una... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73314 json | XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenti... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73313 json | XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an ... | Not Provided | 2026-09-08 | 2026-09-14 |
| CVE-2026-73312 json | XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple t... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73311 json | XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized ... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73310 json | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allow... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-73309 json | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticate... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-35057 json | XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, prima... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-35056 json | XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An at... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-35055 json | XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An att... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-35054 json | XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject ... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2025-71282 json | XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allow... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2025-71281 json | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead... | Not Provided | 2026-04-01 | 2026-04-01 |