Executive brief
XenForo is a popular community forum platform used by businesses to host customer discussions and knowledge bases. A security vulnerability in the RSS feed management system allows authorized users, such as administrators or those with feed-management permissions, to probe the internal network of the server. This could lead to the discovery of private internal services or the exposure of the server's true IP address, potentially bypassing DDoS protection services.
Technical details
An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in XenForo versions up to and including 2.3.8. The flaw is located within the 'add/save RSS feed' endpoint, where the application fails to properly validate or restrict the destination URL for RSS feeds. An attacker with administrative privileges or specific permissions to manage RSS feeds can provide loopback addresses (e.g., 127.0.0.1) or internal IP addresses to perform port scanning of the local server and internal network. This can be used to enumerate internal services or identify the server's origin IP address. As of the disclosure date, the vendor has reportedly not responded to the researchers' findings.
Affected products
- XenForo XenForo 2.3.8 and below
Timeline
- 2026-03-25: other: Vulnerability discovered
- 2026-03-27: other: Initial contact made with XenForo security team
- 2026-07-02: other: CVE-2026-51833 reserved by MITRE
- 2026-07-15: disclosed: Public disclosure by researchers due to vendor silence
- 2026-07-17: advisory: NVD publication date