CVE-2026-35057
- EPSS 0.03%
- Veröffentlicht 01.04.2026 00:30:14
- Zuletzt bearbeitet 01.04.2026 16:24:40
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored...
CVE-2026-35055
- EPSS 0.03%
- Veröffentlicht 01.04.2026 00:30:13
- Zuletzt bearbeitet 01.04.2026 18:55:13
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
CVE-2026-35056
- EPSS 0.43%
- Veröffentlicht 01.04.2026 00:30:13
- Zuletzt bearbeitet 01.04.2026 18:55:19
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
CVE-2026-35054
- EPSS 0.03%
- Veröffentlicht 01.04.2026 00:30:12
- Zuletzt bearbeitet 01.04.2026 18:51:19
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
CVE-2025-71282
- EPSS 0.04%
- Veröffentlicht 01.04.2026 00:30:11
- Zuletzt bearbeitet 01.04.2026 18:53:29
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
CVE-2025-71280
- EPSS 0.01%
- Veröffentlicht 01.04.2026 00:30:10
- Zuletzt bearbeitet 01.04.2026 18:52:12
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
CVE-2025-71281
- EPSS 0.05%
- Veröffentlicht 01.04.2026 00:30:10
- Zuletzt bearbeitet 01.04.2026 18:52:54
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially ...
CVE-2025-71279
- EPSS 0.11%
- Veröffentlicht 01.04.2026 00:30:09
- Zuletzt bearbeitet 01.04.2026 18:57:17
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
CVE-2025-71278
- EPSS 0.04%
- Veröffentlicht 01.04.2026 00:30:08
- Zuletzt bearbeitet 01.04.2026 18:51:48
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their i...
CVE-2024-58342
- EPSS 0.03%
- Veröffentlicht 01.04.2026 00:30:07
- Zuletzt bearbeitet 01.04.2026 18:54:10
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs ...