CVE-2025-71281
- EPSS 0.33%
- Veröffentlicht 01.04.2026 00:30:10
- Zuletzt bearbeitet 01.04.2026 18:52:54
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially ...
CVE-2025-71280
- EPSS 0.12%
- Veröffentlicht 01.04.2026 00:30:10
- Zuletzt bearbeitet 01.04.2026 18:52:12
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
CVE-2025-71279
- EPSS 0.45%
- Veröffentlicht 01.04.2026 00:30:09
- Zuletzt bearbeitet 01.04.2026 18:57:17
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
CVE-2025-71278
- EPSS 0.27%
- Veröffentlicht 01.04.2026 00:30:08
- Zuletzt bearbeitet 01.04.2026 18:51:48
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their i...
CVE-2024-58342
- EPSS 0.15%
- Veröffentlicht 01.04.2026 00:30:07
- Zuletzt bearbeitet 01.04.2026 18:54:10
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs ...
CVE-2023-53904
- EPSS 0.26%
- Veröffentlicht 17.12.2025 22:44:43
- Zuletzt bearbeitet 15.04.2026 00:35:42
Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that ...
CVE-2024-38458
- EPSS 0.89%
- Veröffentlicht 16.06.2024 15:15:51
- Zuletzt bearbeitet 21.11.2024 09:25:56
Xenforo before 2.2.16 allows code injection.
CVE-2024-38457
- EPSS 7.41%
- Veröffentlicht 16.06.2024 15:15:51
- Zuletzt bearbeitet 21.11.2024 09:25:56
Xenforo before 2.2.16 allows CSRF.
CVE-2024-25006
- EPSS 1.02%
- Veröffentlicht 29.02.2024 01:44:14
- Zuletzt bearbeitet 08.05.2025 22:45:31
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
CVE-2021-43032
- EPSS 0.9%
- Veröffentlicht 03.11.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:28:33
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.