Technology · XenForo Ltd.
XenForo Ltd. Xenforo vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in XenForo Ltd. Xenforo: 0 in the last 7 days and 15 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-74239, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 15
- Critical, all time
- 0
- Exploited in the wild
- 0
About XenForo Ltd. Xenforo
A commercial forum software and content management system built on the Zend Framework.
Latest XenForo Ltd. Xenforo vulnerabilities
- CVE-2026-74239: XenForo path traversal in style archive importer on WindowshighCVSS 7.2EPSS 0.9%
- CVE-2026-73321: XenForo stack overflow in BBCode parsermediumCVSS 6.5EPSS 0.6%
- CVE-2026-73320: XenForo unauthenticated information disclosure via unfurl endpointmediumCVSS 6.1EPSS 0.4%
- CVE-2026-73319: XenForo cross-site scripting in dynamic redirect handlermediumCVSS 6.1EPSS 0.4%
- CVE-2026-73318: XenForo missing authorization in force-agreement controllerlowCVSS 3.8EPSS 0.5%
- CVE-2026-73317: XenForo authorization bypass in ACP cache-rebuild dispatcherlowCVSS 2.7EPSS 0.4%
- CVE-2026-73316: XenForo PayPal REST webhook replay vulnerabilityhighCVSS 7.5EPSS 0.3%
- CVE-2026-73315: XenForo server-side request forgery in PayPal webhook handlerhighCVSS 8.6EPSS 0.4%
- CVE-2026-73314: XenForo PayPal webhook signature verification bypasshighCVSS 7.5EPSS 0.7%
- CVE-2026-73313: XenForo passkey TFA authentication bypassmediumCVSS 6.8EPSS 0.6%
- CVE-2026-73312: XenForo refresh token replay vulnerabilityhighCVSS 7.4EPSS 0.5%
- CVE-2026-73311: XenForo OAuth2 authorization code reuse vulnerabilityhighCVSS 7.4EPSS 0.5%
- CVE-2026-73310: XenForo OAuth2 redirect URI binding bypassmediumCVSS 5.9EPSS 0.5%
- CVE-2026-73309: XenForo authentication bypass in OAuth2 token endpointhighCVSS 7.4EPSS 0.7%
- CVE-2026-51833: XenForo SSRF in RSS feed managementinfoCVSS 0
Most severe XenForo Ltd. Xenforo vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-73315: XenForo server-side request forgery in PayPal webhook handlerhighCVSS 8.6EPSS 0.4%
- CVE-2026-73314: XenForo PayPal webhook signature verification bypasshighCVSS 7.5EPSS 0.7%
- CVE-2026-73316: XenForo PayPal REST webhook replay vulnerabilityhighCVSS 7.5EPSS 0.3%
- CVE-2026-73309: XenForo authentication bypass in OAuth2 token endpointhighCVSS 7.4EPSS 0.7%
- CVE-2026-73311: XenForo OAuth2 authorization code reuse vulnerabilityhighCVSS 7.4EPSS 0.5%
- CVE-2026-73312: XenForo refresh token replay vulnerabilityhighCVSS 7.4EPSS 0.5%
- CVE-2026-74239: XenForo path traversal in style archive importer on WindowshighCVSS 7.2EPSS 0.9%
- CVE-2026-73313: XenForo passkey TFA authentication bypassmediumCVSS 6.8EPSS 0.6%
- CVE-2026-73321: XenForo stack overflow in BBCode parsermediumCVSS 6.5EPSS 0.6%
- CVE-2026-73319: XenForo cross-site scripting in dynamic redirect handlermediumCVSS 6.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 14 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/xenforo.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "XenForo Ltd. Xenforo vulnerabilities", https://junglewise.ai/threats/technologies/xenforo, 26 September 2026.