Xenforo — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
September 8, 2026
Last Seen
September 8, 2026

Related Threat Clusters

  • High-Risk Vulnerabilities in XenForo Payment Processing

    XenForo versions prior to 2.3.13 are affected by two critical vulnerabilities: CVE-2026-73314 and CVE-2026-73315. CVE-2026-73314 allows unauthenticated attackers to bypass PayPal payment signature validation, risking…

    2 articles · Updated September 8, 2026
  • Multiple Vulnerabilities Discovered in Xenforo OAuth2 Implementation

    On September 8, 2026, multiple vulnerabilities were reported in Xenforo's OAuth2 implementation, affecting various systems that utilize this framework. The vulnerabilities include an authentication bypass via the OAuth2…

    5 articles · Updated September 8, 2026
  • Multiple OAuth Vulnerabilities Discovered in XenForo

    XenForo versions prior to 2.3.13 are affected by three critical vulnerabilities: CVE-2026-73311, CVE-2026-73312, and CVE-2026-73309. These vulnerabilities include an OAuth2 authorization code reuse flaw, a refresh token…

    3 articles · Updated September 8, 2026

Recent Intelligence Reports

  • Xenforo Refresh Token Replay Via Expired Access Token — www.vulncheck.com · September 8, 2026
  • Xenforo Signature Verification Bypass Via Paypal Rest Webhook — www.vulncheck.com · September 8, 2026
  • CVE Alert: CVE-2026-73311 – XenForo — Redpacketsecurity · September 8, 2026
  • CVE Alert: CVE-2026-73312 – XenForo — Redpacketsecurity · September 8, 2026
  • CVE Alert: CVE-2026-73309 – XenForo — Redpacketsecurity · September 8, 2026
  • CVE Alert: CVE-2026-73314 – XenForo — Redpacketsecurity · September 8, 2026

CVSS v3.1 Breakdown