Impact
The vulnerability allows an authenticated user to submit a post containing deeply nested BBCode tags that cause the backend parser to exceed PHP’s stack limit, leading to fatal errors. Each fatal error terminates a PHP‑FPM worker, which is subsequently restarted by the server process. Because the thread remains in the forum, visitors who attempt to view it continue to experience repeated crashes, resulting in a sustained denial of service for all users viewing the affected content.
Affected Systems
All installations of XenForo prior to version 2.3.13 are affected. The flaw exists in the BBCode parser component of the XenForo application and impacts any deployment that allows authenticated users to post or edit messages. 2.3.13 and later contain a patch that limits BBCode nesting depth and prevents this recursion.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as high‑severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated to create a post; thus the vector is local to a logged‑in user. Once exploited, the impact is system‑wide availability degradation for the affected forum until a new PHP‑FPM worker is started, and the denial of service becomes persistent until the vulnerable post is removed or the application is patched.
OpenCVE Enrichment