Method Call Restriction Bypass in XenForo by XenForo Limited
CVE-2025-71281
8.7HIGH
What is CVE-2025-71281?
XenForo versions prior to 2.3.7 exhibit a vulnerability where the method restrictions within templates are not adequately enforced. Instead of implementing a stringent first-word match for callable methods, the system uses a loose prefix match. This flaw may permit unauthorized invocations of methods through callbacks and variable method calls within templates, creating a potential security risk for users and their data.
Affected Version(s)
XenForo 2.3.0 < 2.3.7
