PT-2026-29431 · Xenforo · Xenforo

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-35056

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.3.9 and prior to 2.2.18
Description XenForo allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Recommendations Update to XenForo version 2.3.9 or later. Update to XenForo version 2.2.18 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35056

Affected Products

Xenforo