Vulnerabilities
Vulnerable Software
Xenforo:  >> Xenforo  >> 2.1.12  Security Vulnerabilities
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-04-01
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-04-01
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host mismatches.
CVSS Score
5.3
EPSS Score
0.001
Published
2026-04-01
Xenforo before 2.2.16 allows CSRF.
CVSS Score
8.8
EPSS Score
0.074
Published
2024-06-16
Xenforo before 2.2.16 allows code injection.
CVSS Score
8.8
EPSS Score
0.009
Published
2024-06-16
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
CVSS Score
8.1
EPSS Score
0.01
Published
2024-02-29
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.
CVSS Score
4.8
EPSS Score
0.009
Published
2021-11-03


Contact Us

Shodan ® - All rights reserved