Filtered by vendor Xenforo Subscriptions
Filtered by product Xenforo Subscriptions
Total 30 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-58342 1 Xenforo 1 Xenforo 2026-04-02 6.3 Medium
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host mismatches.
CVE-2025-71278 1 Xenforo 1 Xenforo 2026-04-02 8.8 High
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.
CVE-2025-71279 1 Xenforo 1 Xenforo 2026-04-02 9.8 Critical
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
CVE-2025-71280 1 Xenforo 1 Xenforo 2026-04-02 6.2 Medium
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
CVE-2025-71282 1 Xenforo 1 Xenforo 2026-04-02 7.5 High
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
CVE-2026-35054 1 Xenforo 1 Xenforo 2026-04-02 6.4 Medium
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
CVE-2024-25006 1 Xenforo 1 Xenforo 2025-05-08 8.1 High
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
CVE-2024-38458 1 Xenforo 1 Xenforo 2024-11-21 8.8 High
Xenforo before 2.2.16 allows code injection.
CVE-2024-38457 1 Xenforo 1 Xenforo 2024-11-21 8.8 High
Xenforo before 2.2.16 allows CSRF.
CVE-2021-43032 1 Xenforo 1 Xenforo 2024-11-21 4.8 Medium
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.