CVE-2025-71279Disclosure(xenforo / xenforo)

LOWCVSS 9.3 · CRITICAL

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Patch xenforo xenforo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xenforo

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • 7 total mentions across 1 day

Affected systems

Vendors
Products
xenforo

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-04-01: 7Patch / Workaround · 2026-04-01: 2Technical Details · 2026-04-01: 704-01
Signal classification1 categories
Disclosure
7100.0%
Referenced assets6 URLs
Full discourse7 posts
  • X Galdino@galdinociber
    Disclosure

    🚨 CVE-2025-71279: XenForo <2.3.7 tem vulnerabilidade crítica em passkeys. CVSS 9.8. Atacantes podem comprometer autenticação sem credenciais.

    Post summary

    The post announces the discovery of a high‑severity CVE‑2025‑71279 in XenForo systems with a CVSS score of 9.8, but does not provide PoC, exploit code, or patch information.

    00000248
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71279 XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey… https://www.cve.org/CVERecord?id=CVE-2025-71279

    Post summary

    The text provides a brief disclosure of CVE-2025-71279, noting a passkey security issue in XenForo that could allow attacker compromise, but does not mention PoC, exploit code, active usage, patch, or false positive information.

    00000164
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-71279 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-71279 #CVE-2025-71279 #CVE #Critical #CyberSecurity #InfoSec https://t.co/cdO2EzKRMh

    Post summary

    The post announces a newly identified CVE-2025-71279 with a high severity score and references the official NVD entry, but provides no exploit, PoC, or mitigation details.

    00000139
    123 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    XenForo Passkey Flaw CVE-2025-71279 Enables Critical Security Bypass https://cybersecuritypath.com/xenforo-passkey-flaw-cve-2025-71279-enables-critical-security-bypass/ #cybersecuritynews #XenForo

    Post summary

    The article announces a new XenForo Passkey flaw (CVE-2025-71279) that allows a critical security bypass, but provides no details on PoCs, exploit code, active exploitation, or patches.

    00000178
    3 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-71279 - Critical XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication. https://www.thehackerwire.com/vulnerability/CVE-2025-71279/ https://t.co/MOO5GNEw57

    Post summary

    The tweet announces CVE-2025-71279 as a critical vulnerability in XenForo affecting Passkey authentication, but provides no evidence of active exploitation, exploit code, or patch.

    00000186
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-71279: CRITICAL] XenForo <2.3.7 has a security flaw impacting Passkeys in user accounts, compromising authentication security. Keep systems updated for cyber security.#cve,CVE-2025-71279,#cybersecurity https://cvefind.com/CVE-2025-71279

    Post summary

    XenForo versions before 2.3.7 contain a critical flaw that compromises Passkey authentication, necessitating users to update to the latest patched release.

    0000086
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-71279: XenForo Passkey Security Bypass ... Passkey bypass with zero auth requirements and 9.3 CVSS means XenForo forums are wide open—patch immediately before att... https://zerodaysignal.com/vulnerability/CVE-2025-71279 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the CVE-2025-71279 XenForo passkey bypass, noting a zero‑auth bypass and a CVSS score of 9.3, and urges users to apply a patch immediately.

    00000233
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxenforoxenforo---

Explore more