
CVE-2025-71280 XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cache… https://www.cve.org/CVERecord?id=CVE-2025-71280
Post summary
The note announces CVE-2025-71280, detailing an information disclosure flaw in XenForo versions prior to 2.3.7 that arises from caching on shared browsers or machines. No proof‑of‑concept, exploit code, patch, or evidence of active exploitation is provided.

