Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xenforo HIGH 7.2
CVE-2026-35056

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel …

Fix: 2.2.18 / 2.3.9+
Fix from $1,950 2026-04-01
Xenforo MEDIUM 6.1
CVE-2026-35055

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicio…

Fix: 2.2.18 / 2.3.9+
Fix from $1,600 2026-04-01
Xenforo MEDIUM 5.4
CVE-2026-35054

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts throug…

Fix: 2.3.9+
Fix from $1,600 2026-04-01
Xenforo MEDIUM 5.4
CVE-2026-35057

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy pr…

Fix: 2.2.19 / 2.3.10+
Fix from $1,600 2026-04-01
Xenforo CRITICAL 9.8
CVE-2025-71279

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the se…

Fix: 2.3.7+
Fix from $2,300 2026-04-01
Xenforo CRITICAL 9.8
CVE-2025-71281

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor…

Fix: 2.3.7+
Fix from $2,300 2026-04-01
Xenforo HIGH 8.8
CVE-2025-71278

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version …

Fix: 2.3.5+
Fix from $1,950 2026-04-01
Xenforo HIGH 7.5
CVE-2025-71282

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain …

Fix: 2.3.7+
Fix from $1,950 2026-04-01
Xenforo MEDIUM 5.5
CVE-2025-71280

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser …

Fix: 2.3.7+
Fix from $1,600 2026-04-01
Xenforo MEDIUM 6.1
CVE-2024-58342

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the …

Fix: 2.2.17+
Fix from $1,600 2026-04-01
Xenforo HIGH 8.8
CVE-2024-38457EPSS 7%

Xenforo before 2.2.16 allows CSRF.

Fix: 2.2.16+
Fix from $1,950 2024-06-16
Xenforo HIGH 8.8
CVE-2024-38458

Xenforo before 2.2.16 allows code injection.

Fix: 2.2.16+
Fix from $1,950 2024-06-16
Xenforo HIGH 8.1
CVE-2024-25006

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZI…

Fix: 2.2.14+
Fix from $1,950 2024-02-29