Unauthenticated Information Disclosure in XenForo by XenForo Ltd.
CVE-2026-73320
5.1MEDIUM
What is CVE-2026-73320?
The vulnerability in XenForo before version 2.3.13 allows attackers to exploit the unfurl endpoint without requiring authentication. By submitting predictable primary key IDs, an attacker can retrieve sensitive information including rendered HTML previews, original URLs, and query strings from private conversations. This flaw enables unauthorized access to normally restricted content, increasing the potential for data breaches and privacy violations.
Affected Version(s)
XenForo 0 < 2.3.13
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Paciaroni (BomboBombone)
VulnCheck
