XenForo Remote Code Execution Vulnerability for Authenticated Admin Users

Vulnerability

A remote code execution vulnerability has been identified in XenForo versions prior to 2.3.9 and 2.2.18. This vulnerability allows authenticated, malicious admin users to execute arbitrary code on the server.

Impact

Exploitation of this vulnerability allows for remote code execution on the server.

Remediation

Users are advised to upgrade to XenForo 2.3.9 or 2.2.18. For those on XenForo 2.3.7 or earlier, a specific patch is available. Instructions for applying the patch or upgrading are provided in the XenForo community announcement.

Added: Apr 1, 2026, 1:31 AM
Updated: Apr 1, 2026, 1:31 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
10.0
exploitability
5.0
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.