XenForo OAuth2 Unauthorized Scope Request Vulnerability

Vulnerability

An authorization vulnerability exists in XenForo versions prior to 2.3.5, allowing OAuth2 client applications to request unauthorized scopes. This could enable clients to access resources beyond their authorized limits. The issue affects all users of XenForo 2.3 who utilize OAuth2 clients.

Impact

Exploitation of this vulnerability could lead to unauthorized access to resources or functionalities, allowing OAuth2 client applications to operate beyond their intended permissions.

Remediation

Users are advised to upgrade to XenForo version 2.3.5, which includes a critical security fix for this vulnerability. Instructions for upgrading are available on the XenForo website.

Added: Apr 1, 2026, 1:26 AM
Updated: Apr 1, 2026, 1:26 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
6.8
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.