Xenforo
10 known vulnerabilities
Top Products
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions,
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users.
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. A
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can in
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does
Frequently Asked Questions
How many CVEs affect Xenforo?
Xenforo has 10 CVE records in our database, including 1 critical and 4 high severity vulnerabilities.
What are the most severe Xenforo vulnerabilities?
Xenforo has 1 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Xenforo vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Xenforo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Xenforo Vulnerabilities
CyberStrike scans your infrastructure for Xenforo vulnerabilities and provides real-time remediation guidance.
Get Started