Description
XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.
Published: 2026-09-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

XenForo versions prior to 2.3.13 contain a cross‑site scripting flaw in the dynamic redirect handler that allows an attacker who does not need to be authenticated to craft a malicious javascript: URI. By embedding the board hostname in the URI authority and inserting percent‑encoded newlines, the attacker bypasses server‑side host validation checks and causes any authenticated user who follows the crafted link to execute attacker‑supplied JavaScript within the board’s origin context. This can expose session cookies, allow session hijacking, or enable arbitrary actions performed by the user’s browser.

Affected Systems

Affected systems are XenForo installations running any release earlier than 2.3.13.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity vulnerability with a relatively limited scope that requires a user to click a crafted link. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet reported. Nevertheless, because the flaw permits arbitrary JavaScript execution in the context of a valid user session, it presents a significant threat if an attacker can deliver a link to users. The attack vector is remote, unauthenticated, and depends on user interaction.

Generated by OpenCVE AI on September 8, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update XenForo to version 2.3.13 or later, which contains a fix for the redirect handler.
  • If an immediate upgrade is not possible, block or remove support for the "javascript:" scheme in redirects through web‑server or application configuration to prevent the malicious URI from being processed.
  • Implement a strict Content Security Policy that disallows inline scripts and the "javascript:" protocol, and use a web application firewall to detect and block XSS payloads.

Generated by OpenCVE AI on September 8, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.
Title XenForo < 2.3.13 XSS via Dynamic Redirect Handler
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T13:47:19.639Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73319

cve-icon Vulnrichment

Updated: 2026-09-10T13:47:08.954Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:26.333

Modified: 2026-09-11T20:26:33.740

Link: CVE-2026-73319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')