PT-2026-29431 · Xenforo · Xenforo

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-35056

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35056

Affected Products

Xenforo