Xenforo is a community forum and discussion platform with a concentrated vulnerability footprint centered on its flagship product. Vulnerabilities affecting this vendor skew toward serious outcomes and cluster around web-application weakness classes—including cross-site scripting, code injection, CSRF, and improper handling of sensitive information—that are endemic to dynamic content platforms with user-generated input and authentication flows. Defenders should prioritize patches for internet-facing forum instances and review user-permission configurations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xenforo over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-71281CRITICAL XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible | Apr 1, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-71279CRITICAL XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authent | Apr 1, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-71278HIGH XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, | Apr 1, 2026 | 8.8 | 30 | NO | NO |
CVE-2024-38457HIGH Xenforo before 2.2.16 allows CSRF. | Jun 16, 2024 | 8.8 | 29 | NO | NO |
CVE-2026-35056HIGH XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary co | Apr 1, 2026 | 7.2 | 27 | NO | NO |
CVE-2025-71282HIGH XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's | Apr 1, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-38458HIGH Xenforo before 2.2.16 allows code injection. | Jun 16, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-25006HIGH XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import. | Feb 29, 2024 | 8.1 | 23 | NO | NO |
CVE-2026-35054MEDIUM XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and e | Apr 1, 2026 | 6.4 | 22 | NO | NO |
CVE-2025-71280MEDIUM XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account page | Apr 1, 2026 | 6.2 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xenforo.
Media articles that mention a CVE ID that affects a product developed by Xenforo — matched by CVE ID, not by vendor name.