Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-35056 XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel … Xenforo 2.2.18 / 2.3.9+ Fix from $1,9502026-04-01 MEDIUM 6.1 CVE-2026-35055 XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicio… Xenforo 2.2.18 / 2.3.9+ Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-35054 XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts throug… Xenforo 2.3.9+ Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-35057 XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy pr… Xenforo 2.2.19 / 2.3.10+ Fix from $1,6002026-04-01 CRITICAL 9.8 CVE-2025-71279 XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the se… Xenforo 2.3.7+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2025-71281 XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor… Xenforo 2.3.7+ Fix from $2,3002026-04-01 HIGH 8.8 CVE-2025-71278 XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version … Xenforo 2.3.5+ Fix from $1,9502026-04-01 HIGH 7.5 CVE-2025-71282 XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain … Xenforo 2.3.7+ Fix from $1,9502026-04-01 MEDIUM 5.5 CVE-2025-71280 XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser … Xenforo 2.3.7+ Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2024-58342 XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the … Xenforo 2.2.17+ Fix from $1,6002026-04-01 HIGH 8.8 CVE-2024-38457EPSS 7% Xenforo before 2.2.16 allows CSRF. Xenforo 2.2.16+ Fix from $1,9502024-06-16 HIGH 8.8 CVE-2024-38458 Xenforo before 2.2.16 allows code injection. Xenforo 2.2.16+ Fix from $1,9502024-06-16 HIGH 8.1 CVE-2024-25006 XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZI… Xenforo 2.2.14+ Fix from $1,9502024-02-29