Description
XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Persistent Denial of Service via uncontrolled recursion
Action: Patch Now
AI Analysis

Impact

The vulnerability allows an authenticated user to submit a post containing deeply nested BBCode tags that cause the backend parser to exceed PHP’s stack limit, leading to fatal errors. Each fatal error terminates a PHP‑FPM worker, which is subsequently restarted by the server process. Because the thread remains in the forum, visitors who attempt to view it continue to experience repeated crashes, resulting in a sustained denial of service for all users viewing the affected content.

Affected Systems

All installations of XenForo prior to version 2.3.13 are affected. The flaw exists in the BBCode parser component of the XenForo application and impacts any deployment that allows authenticated users to post or edit messages. 2.3.13 and later contain a patch that limits BBCode nesting depth and prevents this recursion.

Risk and Exploitability

The CVSS score of 7.1 marks the issue as high‑severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated to create a post; thus the vector is local to a logged‑in user. Once exploited, the impact is system‑wide availability degradation for the affected forum until a new PHP‑FPM worker is started, and the denial of service becomes persistent until the vulnerable post is removed or the application is patched.

Generated by OpenCVE AI on September 8, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the XenForo update to version 2.3.13 or later to fix the recursion limit in the BBCode parser.
  • Until the update is applied, disable BBCode parsing for new posts or remove the post that triggers the recursion to prevent further crashes.
  • Implement rate limiting on post submissions and monitor PHP-FPM logs for repeated fatal errors to detect potential exploitation attempts early.

Generated by OpenCVE AI on September 8, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.
Title XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T15:02:59.382Z

Reserved: 2026-08-11T19:56:20.008Z

Link: CVE-2026-73321

cve-icon Vulnrichment

Updated: 2026-09-10T13:50:08.414Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:26.617

Modified: 2026-09-11T20:30:18.293

Link: CVE-2026-73321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses