PT-2026-29416 · Xenforo · Xenforo

Hypixel Inc

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2025-71280

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.3.7
Description XenForo before version 2.3.7 allows information disclosure through local account page caching on shared systems. When multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
Recommendations Update to version 2.3.7 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-71280

Affected Products

Xenforo