PT-2026-29417 · Xenforo · Xenforo

Cyanide

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2025-71281

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.3.7
Description XenForo does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.
Recommendations Update to version 2.3.7 or later.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-71281

Affected Products

Xenforo