Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-73312

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.6%
CVSS Severity
CVSS v3 Score 7.4
Products affected by CVE-2026-73312


Contact Us

Shodan ® - All rights reserved