CVE-2025-71280 is an information disclosure vulnerability affecting XenForo versions prior to 2.3.7, where local account page caching on shared systems can expose sensitive user data. Rated Medium with a CVSS score of 6.2, this vulnerability has a local attack vector and low attack complexity, potentially leading to high confidentiality impact by revealing user information to other local users. There is currently no evidence of active exploitation, nor is any public exploit code available, and community discussion or media coverage remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.3.7CPE match | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | ||
< 2.3.7CPE matchmatch criteria | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.