OAuth2 Vulnerability in XenForo Affects User Authorization Levels
CVE-2025-71278
8.7HIGH
What is CVE-2025-71278?
XenForo prior to version 2.3.5 is susceptible to a security flaw that allows OAuth2 client applications to request unauthorized scopes. This vulnerability compromises the integrity of user authorization, enabling client applications to potentially access sensitive information or perform actions beyond their designated permissions. Users of XenForo 2.3 and earlier versions should be aware of this risk and should promptly update to version 2.3.5 or later to secure their applications against unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
XenForo 2.3.0 < 2.3.5
