XenForo Information Disclosure Vulnerability via Local Account Page Caching on Shared Systems

Vulnerability

A vulnerability in XenForo versions prior to 2.3.7 allows for information disclosure through local account page caching on shared systems. In environments where multiple users share a browser or machine, cached account pages may inadvertently reveal sensitive user information to other local users.

Impact

Exploitation of this vulnerability could lead to unauthorized exposure of sensitive user information to other local users on the same system.

Remediation

Users are advised to upgrade to XenForo version 2.3.7 or apply the available patch. Instructions for upgrading and downloading the patch are available on the XenForo community website.

Added: Apr 1, 2026, 1:25 AM
Updated: Apr 1, 2026, 1:25 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.8
exploitability
3.4
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.