xenforo CVE Vulnerabilities & CVE List (14)

Products (CPE): — CVEs: 14

xenforo vulnerability overview

Aggregates CVE and security vulnerability intelligence across all xenforo-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting, vendor risk path handling, and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 114 of 14 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-35057 XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content. [email protected] 5.1 0.17% 2026-04-01 2026-04-01
CVE-2026-35056 XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server. [email protected] 8.6 0.67% 2026-04-01 2026-04-01
CVE-2026-35055 XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox. [email protected] 5.1 0.15% 2026-04-01 2026-04-01
CVE-2026-35054 XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content. [email protected] 5.1 0.14% 2026-04-01 2026-04-01
CVE-2025-71282 XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure. [email protected] 8.7 0.34% 2026-04-01 2026-04-01
CVE-2025-71281 XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations. [email protected] 8.7 0.33% 2026-04-01 2026-04-01
CVE-2025-71280 XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users. [email protected] 6.9 0.12% 2026-04-01 2026-04-01
CVE-2025-71279 XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication. [email protected] 9.3 0.45% 2026-04-01 2026-04-01
CVE-2025-71278 XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level. [email protected] 8.7 0.27% 2026-04-01 2026-04-01
CVE-2024-58342 XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host mismatches. [email protected] 5.3 0.15% 2026-04-01 2026-04-01
CVE-2024-38458 Xenforo before 2.2.16 allows code injection. [email protected] 8.8 0.89% 2024-06-16 2024-11-21
CVE-2024-38457 Xenforo before 2.2.16 allows CSRF. [email protected] 8.8 7.41% 2024-06-16 2024-11-21
CVE-2024-25006 XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import. [email protected] 8.1 1.02% 2024-02-29 2025-05-08
CVE-2021-43032 In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side. [email protected] 4.8 0.90% 2021-11-03 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence