PatchSiren

XenForo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM XenForo CVE published 2026-09-08

CVE-2026-73320

CVE-2026-73320 is an unauthenticated information disclosure vulnerability in XenForo before 2.3.13. Attackers can retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. This vulnerability may impact sites with private content, and defenders should assess exposure and apply patches to prevent potential disclosure of private content. The vulnerability [truncated]

MEDIUM XenForo CVE published 2026-09-08

CVE-2026-73319

CVE-2026-73319 is a cross-site scripting vulnerability in XenForo's dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI. This vulnerability affects XenForo versions prior to 2.3.13. The vulnerability allows attackers to embed the board hostname in the URI authority component and use percent-encoded newli [truncated]

MEDIUM XenForo CVE published 2026-09-08

CVE-2026-73318

CVE-2026-73318 is a missing authorization vulnerability in XenForo's force-agreement controller. This vulnerability allows any ACP administrator to access and submit force-agreement forms, regardless of their assigned permissions. As a result, attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp. This forces all users to re- [truncated]

MEDIUM XenForo CVE published 2026-09-08

CVE-2026-73317

CVE-2026-73317 is a missing authorization vulnerability in XenForo's ACP cache-rebuild dispatcher. Limited administrators with rebuildCache permission can perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. This allows them to approve queued user registrations without required permissions, attributing actions to an impersonated account.

HIGH XenForo CVE published 2026-09-08

CVE-2026-73316

CVE-2026-73316 is a payment replay vulnerability in XenForo's PayPal REST payment provider. The vulnerability allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. This can result in repeated subscription activations and unauthorized account upgrades. Defenders should assess exposure and prioritize verification and remediation to preven [truncated]

HIGH XenForo CVE published 2026-09-08

CVE-2026-73315

CVE-2026-73315 is a high-severity vulnerability in XenForo before version 2.3.13, allowing unauthenticated attackers to make outbound HTTP requests to arbitrary destinations via a crafted certificate URL in PayPal REST webhook headers. This server-side request forgery (SSRF) vulnerability can potentially disclose IAM credentials or enable secondary internal service exploitation.

HIGH XenForo CVE published 2026-09-08

CVE-2026-73314

CVE-2026-73314 is a signature verification logic error in XenForo's PayPal REST webhook handler. This vulnerability allows unauthenticated attackers to bypass payment signature validation. The issue arises when an unsupported auth_algo header value is submitted, causing the verification function to incorrectly return true. As a result, the system processes the payment event without a valid PayPal signatur [truncated]

HIGH XenForo CVE published 2026-09-08

CVE-2026-73313

CVE-2026-73313 is a high-severity vulnerability in XenForo, a popular forum software, that allows an authenticated attacker to bypass multi-factor authentication (MFA) using the passkey TFA provider. This vulnerability affects XenForo versions prior to 2.3.13 and can lead to unauthorized access to user accounts. System administrators and security teams should assess their exposure and prioritize patching [truncated]

CRITICAL XenForo CVE published 2026-09-08

CVE-2026-73311

CVE-2026-73311 is a critical OAuth2 authorization code reuse vulnerability in XenForo before 2.3.13. Attackers can exploit this vulnerability to obtain unauthorized token pairs by submitting a previously used authorization code, bypassing the single-use guarantee of the OAuth2 authorization code flow. This vulnerability allows attackers to potentially gain unauthorized access to user accounts and bypass a [truncated]

HIGH XenForo CVE published 2026-09-08

CVE-2026-73310

CVE-2026-73310 is an authorization flaw in XenForo's OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding. This vulnerability, which has a CVSS score of 8.2, was published on 2026-09-08 and last modified on 2026-09-11. The flaw enables attackers to exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 token [truncated]