CVE-2026-73312
- EPSS 0.35%
- Veröffentlicht 08.09.2026 13:16:53
- Zuletzt bearbeitet 11.09.2026 20:30:57
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly ...
CVE-2026-73311
- EPSS 0.37%
- Veröffentlicht 08.09.2026 13:16:31
- Zuletzt bearbeitet 11.09.2026 20:30:43
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark autho...
CVE-2026-73310
- EPSS 0.36%
- Veröffentlicht 08.09.2026 13:16:14
- Zuletzt bearbeitet 11.09.2026 20:36:03
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authori...
CVE-2026-73309
- EPSS 0.47%
- Veröffentlicht 08.09.2026 13:15:50
- Zuletzt bearbeitet 11.09.2026 20:33:42
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers ...
CVE-2026-51833
- EPSS 0.38%
- Veröffentlicht 17.07.2026 00:00:00
- Zuletzt bearbeitet 23.07.2026 18:17:51
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.
CVE-2026-35057
- EPSS 0.17%
- Veröffentlicht 01.04.2026 00:30:14
- Zuletzt bearbeitet 01.04.2026 16:24:40
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored...
CVE-2026-35056
- EPSS 0.67%
- Veröffentlicht 01.04.2026 00:30:13
- Zuletzt bearbeitet 01.04.2026 18:55:19
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
CVE-2026-35055
- EPSS 0.16%
- Veröffentlicht 01.04.2026 00:30:13
- Zuletzt bearbeitet 01.04.2026 18:55:13
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
CVE-2026-35054
- EPSS 0.14%
- Veröffentlicht 01.04.2026 00:30:12
- Zuletzt bearbeitet 01.04.2026 18:51:19
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
CVE-2025-71282
- EPSS 0.34%
- Veröffentlicht 01.04.2026 00:30:11
- Zuletzt bearbeitet 01.04.2026 18:53:29
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.