Junglewise Threat Intelligence

CVE-2026-51833: XenForo SSRF in RSS feed management

CVE-2026-51833 · Severity: info · CVSS 0 · Published 2026-07-17

Technologies: XenForo. Vendors: XenForo Ltd..

Executive brief

XenForo is a popular community forum platform used by businesses to host customer discussions and knowledge bases. A security vulnerability in the RSS feed management system allows authorized users, such as administrators or those with feed-management permissions, to probe the internal network of the server. This could lead to the discovery of private internal services or the exposure of the server's true IP address, potentially bypassing DDoS protection services.

Technical details

An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in XenForo versions up to and including 2.3.8. The flaw is located within the 'add/save RSS feed' endpoint, where the application fails to properly validate or restrict the destination URL for RSS feeds. An attacker with administrative privileges or specific permissions to manage RSS feeds can provide loopback addresses (e.g., 127.0.0.1) or internal IP addresses to perform port scanning of the local server and internal network. This can be used to enumerate internal services or identify the server's origin IP address. As of the disclosure date, the vendor has reportedly not responded to the researchers' findings.

Affected products

  • XenForo XenForo 2.3.8 and below

Timeline

  • 2026-03-25: other: Vulnerability discovered
  • 2026-03-27: other: Initial contact made with XenForo security team
  • 2026-07-02: other: CVE-2026-51833 reserved by MITRE
  • 2026-07-15: disclosed: Public disclosure by researchers due to vendor silence
  • 2026-07-17: advisory: NVD publication date

References