← back
CVE-2025-71280

XenForo Local Account Page Caching Information Disclosure

CVSS 6.9 MEDIUMEPSS 0.1%CWE-200
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
XenForo · XenForo

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →