Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cyanide

#25855of 53,624
9.8Total CVSS
Vulnerabilities · 1
PT-2026-29417
9.8
2026-04-01
Xenforo · Xenforo · CVE-2025-71281
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.3.7 Description XenForo does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations. Recommendations Update to version 2.3.7 or later.