Vulnerabilities
Vulnerable Software
Xenforo:  >> Xenforo  >> 2.3.6  Security Vulnerabilities
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-04-01
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-04-01


Contact Us

Shodan ® - All rights reserved