xenforo CVE Vulnerabilities & Metrics

Focus on xenforo vulnerabilities and metrics.

Last updated: 01 Oct 2026, 22:25 UTC

About xenforo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with xenforo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total xenforo CVEs: 27
Earliest CVE date: 03 Nov 2021, 20:15 UTC
Latest CVE date: 08 Sep 2026, 14:17 UTC

Latest CVE reference: CVE-2026-74239

Rolling Stats

30-day Count (Rolling): 14
365-day Count (Rolling): 23

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical xenforo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.13

Max CVSS: 3.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 27
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS xenforo CVEs

These are the five CVEs with the highest CVSS scores for xenforo, sorted by severity first and recency.

All CVEs for xenforo

CVE-2026-74239 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators that bypass forward-slash validation to write arbitrary bytes to any web-server-writable path, including the public web root, achieving persistent code execution as the web-server account.

CVE-2026-73321 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.

CVE-2026-73320 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.

CVE-2026-73319 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.

CVE-2026-73318 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.

CVE-2026-73317 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.

CVE-2026-73316 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.

CVE-2026-73315 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.

CVE-2026-73314 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing the caller to treat the fabricated request as verified and process the payment event without a valid PayPal signature.

CVE-2026-73313 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.

CVE-2026-73312 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.

CVE-2026-73311 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.

CVE-2026-73310 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.

CVE-2026-73309 xenforo vulnerability CVSS: 0 08 Sep 2026, 14:17 UTC

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.

CVE-2026-35057 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

CVE-2026-35056 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

CVE-2026-35055 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

CVE-2026-35054 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

CVE-2025-71282 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

CVE-2025-71281 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.

CVE-2025-71280 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.

CVE-2025-71279 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

CVE-2024-58342 xenforo vulnerability CVSS: 0 01 Apr 2026, 01:16 UTC

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host mismatches.

CVE-2024-38458 xenforo vulnerability CVSS: 0 16 Jun 2024, 15:15 UTC

Xenforo before 2.2.16 allows code injection.

CVE-2024-38457 xenforo vulnerability CVSS: 0 16 Jun 2024, 15:15 UTC

Xenforo before 2.2.16 allows CSRF.

CVE-2024-25006 xenforo vulnerability CVSS: 0 29 Feb 2024, 01:44 UTC

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVE-2021-43032 xenforo vulnerability CVSS: 3.5 03 Nov 2021, 20:15 UTC

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.