Description
XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.
Published: 2026-09-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

XenForo versions prior to 2.3.13 contain an unauthenticated information disclosure flaw, classified as CWE-639, that allows attackers to retrieve private unfurl records by supplying predictable auto‑increment primary key IDs to the unfurl endpoint. This manipulation bypasses all session, user, and visibility checks, enabling the extraction of rendered preview HTML, original URLs, and query strings from private conversations and other restricted content, thereby exposing confidential data.

Affected Systems

The affected product is XenForo; all installations running any version earlier than 2.3.13 are vulnerable.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk, and while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the flaw remains exploitable by any unauthenticated user with network access to the unfurl endpoint. Attackers do not need additional credentials, making this vulnerability a straightforward disclosure vector once predictable IDs can be enumerated.

Generated by OpenCVE AI on September 8, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XenForo to version 2.3.13 or later using the official patch released by XenForo.
  • Configure the web server or application firewall to restrict access to the unfurl endpoint to authorized users or block the endpoint entirely.
  • Enable logging for the unfurl endpoint and monitor logs for unusual or unauthorized request patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 8, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.
Title XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T01:11:51.781Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73320

cve-icon Vulnrichment

Updated: 2026-09-08T13:40:59.539Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:26.470

Modified: 2026-09-11T20:30:06.430

Link: CVE-2026-73320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key