Home/Product/xenforo
Product

xenforo

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-35057
< 2.2.19
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily
6.4MEDIUM
CVE-2026-35056
< 2.2.18
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacke
7.2HIGH
CVE-2026-35055
< 2.2.18
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker
6.1MEDIUM
CVE-2026-35054
< 2.3.9
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malic
6.4MEDIUM
CVE-2025-71282
< 2.3.7
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an
7.5HIGH
CVE-2025-71281
< 2.3.7
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a
8.8HIGH
CVE-2025-71280
< 2.3.7
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple use
6.2MEDIUM
CVE-2025-71279
< 2.3.7
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able t
9.8CRITICAL
CVE-2025-71278
>= 2.3.0 and < 2.3.5
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clie
8.8HIGH
CVE-2024-58342
< 2.2.17
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequ
6.3MEDIUM
CVE-2024-38458
< 2.2.16
Xenforo before 2.2.16 allows code injection.
8.8HIGH
CVE-2024-38457
< 2.2.16
Xenforo before 2.2.16 allows CSRF.
8.8HIGH
CVE-2024-25006
< 2.2.14
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer st
8.1HIGH
CVE-2021-43032
<= 2.2.7
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising functio
4.8MEDIUM
threatengine.sh