Xenforo

Xenforo

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 01.04.2026 00:30:07
  • Zuletzt bearbeitet 01.04.2026 18:54:10

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 17.12.2025 22:44:43
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that ...

Exploit
  • EPSS 7.41%
  • Veröffentlicht 16.06.2024 15:15:51
  • Zuletzt bearbeitet 21.11.2024 09:25:56

Xenforo before 2.2.16 allows CSRF.

Exploit
  • EPSS 0.89%
  • Veröffentlicht 16.06.2024 15:15:51
  • Zuletzt bearbeitet 21.11.2024 09:25:56

Xenforo before 2.2.16 allows code injection.

  • EPSS 1.02%
  • Veröffentlicht 29.02.2024 01:44:14
  • Zuletzt bearbeitet 08.05.2025 22:45:31

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

Exploit
  • EPSS 0.9%
  • Veröffentlicht 03.11.2021 20:15:09
  • Zuletzt bearbeitet 21.11.2024 06:28:33

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.