Xenforo · Xenforo · CVE-2025-71280
Name of the Vulnerable Software and Affected Versions
XenForo versions prior to 2.3.7
Description
XenForo before version 2.3.7 allows information disclosure through local account page caching on shared systems. When multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
Recommendations
Update to version 2.3.7 or later.