Unauthenticated Information Disclosure in XenForo by XenForo Ltd.
CVE-2026-73320

5.1MEDIUM

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-73320?

The vulnerability in XenForo before version 2.3.13 allows attackers to exploit the unfurl endpoint without requiring authentication. By submitting predictable primary key IDs, an attacker can retrieve sensitive information including rendered HTML previews, original URLs, and query strings from private conversations. This flaw enables unauthorized access to normally restricted content, increasing the potential for data breaches and privacy violations.

Affected Version(s)

XenForo 0 < 2.3.13

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
VulnCheck
.