Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xenforo

First CVE: Nov 3, 2021Active for: 5 yearsTotal CVEs: 14
38.3
VTI Score
Medium

Xenforo is a community forum and discussion platform with a concentrated vulnerability footprint centered on its flagship product. Vulnerabilities affecting this vendor skew toward serious outcomes and cluster around web-application weakness classes—including cross-site scripting, code injection, CSRF, and improper handling of sensitive information—that are endemic to dynamic content platforms with user-generated input and authentication flows. Defenders should prioritize patches for internet-facing forum instances and review user-permission configurations; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xenforo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2021
4 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-71281CRITICAL
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible
Apr 1, 20269.833NONO
CVE-2025-71279CRITICAL
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authent
Apr 1, 20269.833NONO
CVE-2025-71278HIGH
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5,
Apr 1, 20268.830NONO
CVE-2024-38457HIGH
Xenforo before 2.2.16 allows CSRF.
Jun 16, 20248.829NONO
CVE-2026-35056HIGH
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary co
Apr 1, 20267.227NONO
CVE-2025-71282HIGH
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's
Apr 1, 20267.526NONO
CVE-2024-38458HIGH
Xenforo before 2.2.16 allows code injection.
Jun 16, 20248.826NONO
CVE-2024-25006HIGH
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
Feb 29, 20248.123NONO
CVE-2026-35054MEDIUM
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and e
Apr 1, 20266.422NONO
CVE-2025-71280MEDIUM
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account page
Apr 1, 20266.222NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
43%
43%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (64.3%)
Unknown0 (0.0%)
Required5 (35.7%)
Privileges Required
Low6 (42.9%)
High1 (7.1%)
None7 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xenforo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xenforo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xenforo's Products

View all 2 CNAs →

Top CWEs