CVE-2025-71281 is a critical vulnerability affecting XenForo versions prior to 2.3.7, stemming from insufficient restrictions on methods callable from within templates. This flaw allows unauthorized method invocations due to a loose prefix matching mechanism used for callbacks and variable method calls. Rated 9.8 Critical (CVSS:3.1/AV:N/AC:L), it presents a low-complexity attack vector that can be exploited remotely without user interaction, leading to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and public exploit code is unavailable on platforms like Metasploit or ExploitDB. While not on the CISA KEV catalog, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.3.7CPE match | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | ||
< 2.3.7CPE matchmatch criteria | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.