CVE-2026-74239
- EPSS 0.66%
- Veröffentlicht 08.09.2026 13:20:34
- Zuletzt bearbeitet 11.09.2026 20:30:32
XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction dire...
CVE-2026-73321
- EPSS 0.38%
- Veröffentlicht 08.09.2026 13:20:16
- Zuletzt bearbeitet 11.09.2026 20:30:18
XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single ma...
CVE-2026-73320
- EPSS 0.25%
- Veröffentlicht 08.09.2026 13:19:57
- Zuletzt bearbeitet 11.09.2026 20:30:06
XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers ...
CVE-2026-73319
- EPSS 0.29%
- Veröffentlicht 08.09.2026 13:19:39
- Zuletzt bearbeitet 11.09.2026 20:26:33
XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host v...
CVE-2026-73318
- EPSS 0.32%
- Veröffentlicht 08.09.2026 13:19:14
- Zuletzt bearbeitet 14.09.2026 20:16:50
XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the opt...
CVE-2026-73317
- EPSS 0.27%
- Veröffentlicht 08.09.2026 13:18:55
- Zuletzt bearbeitet 11.09.2026 20:26:12
XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary...
CVE-2026-73316
- EPSS 0.2%
- Veröffentlicht 08.09.2026 13:18:35
- Zuletzt bearbeitet 11.09.2026 20:31:36
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a ...
CVE-2026-73315
- EPSS 0.27%
- Veröffentlicht 08.09.2026 13:18:16
- Zuletzt bearbeitet 11.09.2026 20:31:26
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted ce...
CVE-2026-73314
- EPSS 0.45%
- Veröffentlicht 08.09.2026 13:17:52
- Zuletzt bearbeitet 11.09.2026 20:31:16
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header v...
CVE-2026-73313
- EPSS 0.39%
- Veröffentlicht 08.09.2026 13:17:30
- Zuletzt bearbeitet 14.09.2026 20:16:50
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the Web...