CRITICAL 9.1 NVD

CVE-2026-73311

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previou

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.

Affected Products

References

Published: 2026-09-08 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-08 via NVD. Affected: xenforo/xenforo.

Risk Timeline

CVE Disclosed2026-09-08 · 2 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-73309XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuCRITICAL9.1
CVE-2026-73312XenForo before 2.3.13 contains a refresh token replay vulnerability that allows CRITICAL9.1
CVE-2026-73314XenForo before 2.3.13 contains a signature verification logic error in the PayPaHIGH8.7
CVE-2026-73316XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal RESTHIGH8.7
CVE-2026-74239XenForo before 2.3.13 contains a path traversal vulnerability in the style archiHIGH8.6
CVE-2026-73310XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoinHIGH8.2
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.