XenForo

14 known vulnerabilities in XenForo, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-74239 CVSS 8.6 high XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows…
  • CVE-2026-73321 CVSS 7.1 high XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause…
  • CVE-2026-73320 CVSS 5.1 medium XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve…
  • CVE-2026-73319 CVSS 5.1 medium XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers…
  • CVE-2026-73318 CVSS 5.1 medium XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator…
  • CVE-2026-73317 CVSS 5.1 medium XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited…
  • CVE-2026-73316 CVSS 8.7 high XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the…
  • CVE-2026-73315 CVSS 7.7 high XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated…
  • CVE-2026-73314 CVSS 8.7 high XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated…
  • CVE-2026-73313 CVSS 7.6 high XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated…
  • CVE-2026-73312 CVSS 9.1 critical XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by…
  • CVE-2026-73311 CVSS 9.1 critical XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs…
  • CVE-2026-73310 CVSS 8.2 high XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted…
  • CVE-2026-73309 CVSS 9.1 critical XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers…