CVE-2025-71278 Details
Description
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.
An authorization vulnerability exists in XenForo versions prior to 2.3.5, allowing OAuth2 client applications to request unauthorized scopes. This could enable clients to access resources beyond their authorized limits. The issue affects all users of XenForo 2.3 who utilize OAuth2 clients.
Users are advised to upgrade to XenForo version 2.3.5, which includes a critical security fix for this vulnerability. Instructions for upgrading are available on the XenForo website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/xenforo-oauth2-unauthorized-scope-request | [email protected] | Third Party Advisory |
| https://xenforo.com/community/threads/xenforo-2-3-5-includes-security-fix-add-ons-released.228812/ | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xenforo xenforo | >= 2.3.0, < 2.3.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |