PT-2026-29417 · Xenforo · Xenforo
Cyanide
·
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2025-71281
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XenForo versions prior to 2.3.7
Description
XenForo does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.
Recommendations
Update to version 2.3.7 or later.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xenforo