{"schema_version":1,"title":"XenForo Ltd. Xenforo vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in XenForo Ltd. Xenforo: 0 in the last 7 days and 15 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-74239, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/xenforo","json_url":"https://junglewise.ai/threats/technologies/xenforo.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/xenforo","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":14,"last_90_days":15,"last_365_days":15},"latest":[{"cve":"CVE-2026-74239","cvss":7.2,"epss":0.0089,"slug":"cve-2026-74239-xenforo-path-traversal-in-style-archive-importer-on-windows","title":"XenForo path traversal in style archive importer on Windows","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:26.75+00:00","url":"https://junglewise.ai/threats/cve-2026-74239-xenforo-path-traversal-in-style-archive-importer-on-windows"},{"cve":"CVE-2026-73321","cvss":6.5,"epss":0.0061,"slug":"cve-2026-73321-xenforo-stack-overflow-in-bbcode-parser","title":"XenForo stack overflow in BBCode parser","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:26.617+00:00","url":"https://junglewise.ai/threats/cve-2026-73321-xenforo-stack-overflow-in-bbcode-parser"},{"cve":"CVE-2026-73320","cvss":6.1,"epss":0.0036,"slug":"cve-2026-73320-xenforo-unauthenticated-information-disclosure-via-unfurl","title":"XenForo unauthenticated information disclosure via unfurl endpoint","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:26.47+00:00","url":"https://junglewise.ai/threats/cve-2026-73320-xenforo-unauthenticated-information-disclosure-via-unfurl"},{"cve":"CVE-2026-73319","cvss":6.1,"epss":0.0041,"slug":"cve-2026-73319-xenforo-cross-site-scripting-in-dynamic-redirect-handler","title":"XenForo cross-site scripting in dynamic redirect handler","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:26.333+00:00","url":"https://junglewise.ai/threats/cve-2026-73319-xenforo-cross-site-scripting-in-dynamic-redirect-handler"},{"cve":"CVE-2026-73318","cvss":3.8,"epss":0.0049,"slug":"cve-2026-73318-xenforo-missing-authorization-in-force-agreement-controller","title":"XenForo missing authorization in force-agreement controller","severity":"low","exploited":false,"published_at":"2026-09-08T14:17:26.197+00:00","url":"https://junglewise.ai/threats/cve-2026-73318-xenforo-missing-authorization-in-force-agreement-controller"},{"cve":"CVE-2026-73317","cvss":2.7,"epss":0.0041,"slug":"cve-2026-73317-xenforo-authorization-bypass-in-acp-cache-rebuild-dispatcher","title":"XenForo authorization bypass in ACP cache-rebuild dispatcher","severity":"low","exploited":false,"published_at":"2026-09-08T14:17:26.06+00:00","url":"https://junglewise.ai/threats/cve-2026-73317-xenforo-authorization-bypass-in-acp-cache-rebuild-dispatcher"},{"cve":"CVE-2026-73316","cvss":7.5,"epss":0.0027,"slug":"cve-2026-73316-xenforo-paypal-rest-webhook-replay-vulnerability","title":"XenForo PayPal REST webhook replay vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.923+00:00","url":"https://junglewise.ai/threats/cve-2026-73316-xenforo-paypal-rest-webhook-replay-vulnerability"},{"cve":"CVE-2026-73315","cvss":8.6,"epss":0.0036,"slug":"cve-2026-73315-xenforo-server-side-request-forgery-in-paypal-webhook-handler","title":"XenForo server-side request forgery in PayPal webhook handler","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.78+00:00","url":"https://junglewise.ai/threats/cve-2026-73315-xenforo-server-side-request-forgery-in-paypal-webhook-handler"},{"cve":"CVE-2026-73314","cvss":7.5,"epss":0.0065,"slug":"cve-2026-73314-xenforo-paypal-webhook-signature-verification-bypass","title":"XenForo PayPal webhook signature verification bypass","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.64+00:00","url":"https://junglewise.ai/threats/cve-2026-73314-xenforo-paypal-webhook-signature-verification-bypass"},{"cve":"CVE-2026-73313","cvss":6.8,"epss":0.0058,"slug":"cve-2026-73313-xenforo-passkey-tfa-authentication-bypass","title":"XenForo passkey TFA authentication bypass","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:25.5+00:00","url":"https://junglewise.ai/threats/cve-2026-73313-xenforo-passkey-tfa-authentication-bypass"},{"cve":"CVE-2026-73312","cvss":7.4,"epss":0.0047,"slug":"cve-2026-73312-xenforo-refresh-token-replay-vulnerability","title":"XenForo refresh token replay vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.353+00:00","url":"https://junglewise.ai/threats/cve-2026-73312-xenforo-refresh-token-replay-vulnerability"},{"cve":"CVE-2026-73311","cvss":7.4,"epss":0.005,"slug":"cve-2026-73311-xenforo-oauth2-authorization-code-reuse-vulnerability","title":"XenForo OAuth2 authorization code reuse vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.22+00:00","url":"https://junglewise.ai/threats/cve-2026-73311-xenforo-oauth2-authorization-code-reuse-vulnerability"},{"cve":"CVE-2026-73310","cvss":5.9,"epss":0.0049,"slug":"cve-2026-73310-xenforo-oauth2-redirect-uri-binding-bypass","title":"XenForo OAuth2 redirect URI binding bypass","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:25.073+00:00","url":"https://junglewise.ai/threats/cve-2026-73310-xenforo-oauth2-redirect-uri-binding-bypass"},{"cve":"CVE-2026-73309","cvss":7.4,"epss":0.0069,"slug":"cve-2026-73309-xenforo-authentication-bypass-in-oauth2-token-endpoint","title":"XenForo authentication bypass in OAuth2 token endpoint","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:24.913+00:00","url":"https://junglewise.ai/threats/cve-2026-73309-xenforo-authentication-bypass-in-oauth2-token-endpoint"},{"cve":"CVE-2026-51833","cvss":0,"slug":"cve-2026-51833-xenforo-ssrf-in-rss-feed-management","title":"XenForo SSRF in RSS feed management","severity":"info","exploited":false,"published_at":"2026-07-17T20:17:24.99+00:00","url":"https://junglewise.ai/threats/cve-2026-51833-xenforo-ssrf-in-rss-feed-management"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":14},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"XenForo Ltd. Xenforo","slug":"xenforo","vendor":{"name":"XenForo Ltd.","slug":"xenforo-ltd","url":"https://junglewise.ai/threats/vendors/xenforo-ltd"},"aliases":[],"category":"cms","homepage":"https://xenforo.com/","repo_url":"https://github.com/xenforo-ltd/","description":"A commercial forum software and content management system built on the Zend Framework.","url":"https://junglewise.ai/threats/technologies/xenforo"},"most_severe":[{"cve":"CVE-2026-73315","cvss":8.6,"epss":0.0036,"slug":"cve-2026-73315-xenforo-server-side-request-forgery-in-paypal-webhook-handler","title":"XenForo server-side request forgery in PayPal webhook handler","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.78+00:00","url":"https://junglewise.ai/threats/cve-2026-73315-xenforo-server-side-request-forgery-in-paypal-webhook-handler"},{"cve":"CVE-2026-73314","cvss":7.5,"epss":0.0065,"slug":"cve-2026-73314-xenforo-paypal-webhook-signature-verification-bypass","title":"XenForo PayPal webhook signature verification bypass","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.64+00:00","url":"https://junglewise.ai/threats/cve-2026-73314-xenforo-paypal-webhook-signature-verification-bypass"},{"cve":"CVE-2026-73316","cvss":7.5,"epss":0.0027,"slug":"cve-2026-73316-xenforo-paypal-rest-webhook-replay-vulnerability","title":"XenForo PayPal REST webhook replay vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.923+00:00","url":"https://junglewise.ai/threats/cve-2026-73316-xenforo-paypal-rest-webhook-replay-vulnerability"},{"cve":"CVE-2026-73309","cvss":7.4,"epss":0.0069,"slug":"cve-2026-73309-xenforo-authentication-bypass-in-oauth2-token-endpoint","title":"XenForo authentication bypass in OAuth2 token endpoint","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:24.913+00:00","url":"https://junglewise.ai/threats/cve-2026-73309-xenforo-authentication-bypass-in-oauth2-token-endpoint"},{"cve":"CVE-2026-73311","cvss":7.4,"epss":0.005,"slug":"cve-2026-73311-xenforo-oauth2-authorization-code-reuse-vulnerability","title":"XenForo OAuth2 authorization code reuse vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.22+00:00","url":"https://junglewise.ai/threats/cve-2026-73311-xenforo-oauth2-authorization-code-reuse-vulnerability"},{"cve":"CVE-2026-73312","cvss":7.4,"epss":0.0047,"slug":"cve-2026-73312-xenforo-refresh-token-replay-vulnerability","title":"XenForo refresh token replay vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:25.353+00:00","url":"https://junglewise.ai/threats/cve-2026-73312-xenforo-refresh-token-replay-vulnerability"},{"cve":"CVE-2026-74239","cvss":7.2,"epss":0.0089,"slug":"cve-2026-74239-xenforo-path-traversal-in-style-archive-importer-on-windows","title":"XenForo path traversal in style archive importer on Windows","severity":"high","exploited":false,"published_at":"2026-09-08T14:17:26.75+00:00","url":"https://junglewise.ai/threats/cve-2026-74239-xenforo-path-traversal-in-style-archive-importer-on-windows"},{"cve":"CVE-2026-73313","cvss":6.8,"epss":0.0058,"slug":"cve-2026-73313-xenforo-passkey-tfa-authentication-bypass","title":"XenForo passkey TFA authentication bypass","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:25.5+00:00","url":"https://junglewise.ai/threats/cve-2026-73313-xenforo-passkey-tfa-authentication-bypass"},{"cve":"CVE-2026-73321","cvss":6.5,"epss":0.0061,"slug":"cve-2026-73321-xenforo-stack-overflow-in-bbcode-parser","title":"XenForo stack overflow in BBCode parser","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:26.617+00:00","url":"https://junglewise.ai/threats/cve-2026-73321-xenforo-stack-overflow-in-bbcode-parser"},{"cve":"CVE-2026-73319","cvss":6.1,"epss":0.0041,"slug":"cve-2026-73319-xenforo-cross-site-scripting-in-dynamic-redirect-handler","title":"XenForo cross-site scripting in dynamic redirect handler","severity":"medium","exploited":false,"published_at":"2026-09-08T14:17:26.333+00:00","url":"https://junglewise.ai/threats/cve-2026-73319-xenforo-cross-site-scripting-in-dynamic-redirect-handler"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}