CVE-2025-71278Disclosure(xenforo / xenforo)

LOWCVSS 8.7 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch xenforo xenforo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xenforo

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
xenforo

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-01: 4Patch / Workaround · 2026-04-01: 1Technical Details · 2026-04-01: 304-01
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-71278 XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 pr… https://www.cve.org/CVERecord?id=CVE-2025-71278

    Post summary

    The text announces CVE‑2025‑71278, explaining that XenForo versions before 2.3.5 permit OAuth2 clients to request unauthorized scopes, with no PoC, patch, or exploitation details included.

    00000153
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-71278 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-71278 #CVE-2025-71278 #CVE #High #CyberSecurity #InfoSec https://t.co/JeIqmiJrcY

    Post summary

    The tweet simply announces CVE-2025-71278 with a high severity score, providing no further technical, exploit, or mitigation information.

    00000158
    123 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-71278 - High XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially... https://www.thehackerwire.com/vulnerability/CVE-2025-71278/ https://t.co/bWWuFMxjeq

    Post summary

    CVE‑2025‑71278 is a high severity vulnerability identified in XenForo versions prior to 2.3.5, allowing OAuth2 clients to obtain unauthorized scopes; the announcement emphasizes the initial details without indicating active exploits or available fixes.

    00000183
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-71278: HIGH] XenForo security alert: Before version 2.3.5, OAuth2 clients could request unauthorized scopes, potentially gaining access beyond their intended level. Update now to stay secure!#cve,CVE-2025-71278,#cybersecurity https://cvefind.com/CVE-2025-71278

    Post summary

    The advisory highlights the CVE-2025-71278 threat in XenForo, provides technical details about unauthorized OAuth2 scopes, and urges users to update to version 2.3.5 to patch the vulnerability.

    0000085
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxenforoxenforo---

Explore more