5.1

CVSS4.0

CVE-2026-35055 - XenForo Cross-Site Scripting via Lightbox in Posts

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:18 p.m.

5.1

CVSS4.0

CVE-2026-35054 - XenForo Stored Cross-Site Scripting via BB Code Rendering

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:09 p.m.

8.7

CVSS4.0

CVE-2025-71282 - XenForo Path Disclosure via open_basedir Exceptions

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:09 p.m.

8.7

CVSS4.0

CVE-2025-71281 - XenForo Template Method Call Restriction Bypass

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:43 p.m.

6.9

CVSS4.0

CVE-2025-71280 - XenForo Local Account Page Caching Information Disclosure

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:09 p.m.

9.3

CVSS4.0

CVE-2025-71279 - XenForo Passkey Security Bypass

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:09 p.m.

8.7

CVSS4.0

CVE-2025-71278 - XenForo OAuth2 Unauthorized Scope Request

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:09 p.m.

5.3

CVSS4.0

CVE-2024-58342 - XenForo Open Redirect via getDynamicRedirect

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host miโ€ฆ

๐Ÿ“… Published: April 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:09 p.m.

7.6

CVSS3.1

CVE-2025-13855 - IBM Storage Protect Server is affected by a vulnerability that could allow authenticated users to aโ€ฆ

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

๐Ÿ“… Published: April 1, 2026, 12:23 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:19 a.m.

9.8

CVSS3.1

CVE-2026-31027 -

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially โ€ฆ

๐Ÿ“… Published: April 1, 2026, midnight ๐Ÿ”„ Last Modified: April 8, 2026, 7:59 p.m.
Total resulsts: 349182
Page 760 of 34,919
ยซ previous page ยป next page
Filters