CRITICALVulnerability
Verified
Global

NVD Critical: CVE-2025-71281 — XenForo before 2.3.7 does not properly restrict methods callable from within tem...

Wednesday, April 1, 2026 at 01:16 AM UTC·Source: NIST NVD

Updated: Wednesday, April 1, 2026 at 07:13 PM UTC

Executive Summary

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.

Analysis

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations. CVSS Score: 8.8. Published: 2026-04-01T01:16:40.590.

Indicators of Compromise (1)

CVE (1)
CVE-2025-71281
Source Attribution

Originally published by NIST NVD on Apr 1, 2026. Verified by: NIST.

Related Threats