Xenforo

Xenforo

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Veröffentlicht 08.09.2026 13:16:53
  • Zuletzt bearbeitet 11.09.2026 20:30:57

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly ...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 08.09.2026 13:16:31
  • Zuletzt bearbeitet 11.09.2026 20:30:43

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark autho...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 08.09.2026 13:16:14
  • Zuletzt bearbeitet 11.09.2026 20:36:03

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authori...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 08.09.2026 13:15:50
  • Zuletzt bearbeitet 11.09.2026 20:33:42

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers ...

  • EPSS 0.38%
  • Veröffentlicht 17.07.2026 00:00:00
  • Zuletzt bearbeitet 23.07.2026 18:17:51

Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 01.04.2026 00:30:14
  • Zuletzt bearbeitet 01.04.2026 16:24:40

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored...

  • EPSS 0.67%
  • Veröffentlicht 01.04.2026 00:30:13
  • Zuletzt bearbeitet 01.04.2026 18:55:19

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

  • EPSS 0.16%
  • Veröffentlicht 01.04.2026 00:30:13
  • Zuletzt bearbeitet 01.04.2026 18:55:13

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

  • EPSS 0.14%
  • Veröffentlicht 01.04.2026 00:30:12
  • Zuletzt bearbeitet 01.04.2026 18:51:19

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

  • EPSS 0.34%
  • Veröffentlicht 01.04.2026 00:30:11
  • Zuletzt bearbeitet 01.04.2026 18:53:29

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.