CVE-2025-71281 Details
Description
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.
A vulnerability exists in XenForo versions prior to 2.3.7, where the framework does not adequately restrict methods that can be called within templates. This flaw arises from the use of a lenient prefix matching system, allowing potentially unauthorized method calls through callbacks and variable method invocations in templates.
Users are advised to upgrade to XenForo version 2.3.7 or apply the available patch. Instructions for upgrading and applying the patch can be found in the XenForo 2.3.7 release announcement.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/xenforo-template-method-call-restriction-bypass | [email protected] | Third Party Advisory |
| https://xenforo.com/community/threads/xenforo-2-3-7-released-includes-security-fixes.232121/ | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xenforo xenforo | < 2.3.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |