Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Xenforo

10 known vulnerabilities

1
CRITICAL
4
HIGH
5
MEDIUM

Top Products

xenforo 10
10 CVEs
6.4
CVE-2026-35057

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions,

7.2
CVE-2026-35056

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users.

6.1
CVE-2026-35055

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. A

6.4
CVE-2026-35054

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can in

7.5
CVE-2025-71282

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This

8.8
CVE-2025-71281

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in

6.2
CVE-2025-71280

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu

9.8
CVE-2025-71279

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may

8.8
CVE-2025-71278

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O

6.3
CVE-2024-58342

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does

Frequently Asked Questions

How many CVEs affect Xenforo?

Xenforo has 10 CVE records in our database, including 1 critical and 4 high severity vulnerabilities.

What are the most severe Xenforo vulnerabilities?

Xenforo has 1 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Xenforo vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Xenforo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Xenforo Vulnerabilities

CyberStrike scans your infrastructure for Xenforo vulnerabilities and provides real-time remediation guidance.

Get Started