Server-Side Request Forgery in XenForo PayPal Webhook Handler
CVE-2026-73315

7.7HIGH

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-73315?

XenForo prior to version 2.3.13 is susceptible to a server-side request forgery vulnerability in its PayPal REST webhook handler. This vulnerability allows unauthenticated attackers to manipulate the server into making outbound HTTP requests to arbitrary destinations. By providing a specially crafted certificate URL within the webhook headers, which bypasses necessary scheme and hostname validations, attackers can exploit the vulnerability. Such attacks could potentially access sensitive internal network resources, including cloud instance metadata services, leading to the exposure of IAM credentials and facilitating further exploitation of internal services.

Affected Version(s)

XenForo 0 < 2.3.13

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
VulnCheck
.