Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-73310

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 29.4%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2026-73310


Contact Us

Shodan ® - All rights reserved