OAuth2 Vulnerability in XenForo Affects User Authorization Levels
CVE-2025-71278

8.7HIGH

Key Information:

Vendor
CVE Published:
1 April 2026

What is CVE-2025-71278?

XenForo prior to version 2.3.5 is susceptible to a security flaw that allows OAuth2 client applications to request unauthorized scopes. This vulnerability compromises the integrity of user authorization, enabling client applications to potentially access sensitive information or perform actions beyond their designated permissions. Users of XenForo 2.3 and earlier versions should be aware of this risk and should promptly update to version 2.3.5 or later to secure their applications against unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

XenForo 2.3.0 < 2.3.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.