Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Cyanide

#25701of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2026-29417
9.8
2026-04-01
Xenforo · Xenforo · CVE-2025-71281
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.3.7 Description XenForo does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations. Recommendations Update to version 2.3.7 or later.