Vulnerabilities
Vulnerable Software
Xenforo:  >> Xenforo  >> 2.3.8  Security Vulnerabilities
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
CVSS Score
5.1
EPSS Score
0.0
Published
2026-04-01
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
CVSS Score
5.1
EPSS Score
0.0
Published
2026-04-01
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
CVSS Score
8.6
EPSS Score
0.004
Published
2026-04-01
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
CVSS Score
5.1
EPSS Score
0.0
Published
2026-04-01


Contact Us

Shodan ® - All rights reserved