CRITICAL 9.1 NVD
CVE-2026-73312
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to m
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
Affected Products
- xenforo/xenforo
References
- https://bombobombone.github.io/posts/cve-2026-73312/
- https://github.com/BomboBombone/CVE-2026-73312
- https://www.vulncheck.com/advisories/xenforo-refresh-token-replay-via-expired-access-token
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-ga
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-securit
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-08 via NVD. Affected: xenforo/xenforo.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
Remediation Resources
Official Advisory
bombobombone.github.io/posts/cve-2026-73312/Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-73309 | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAu | CRITICAL | 9.1 |
| CVE-2026-73311 | XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability | CRITICAL | 9.1 |
| CVE-2026-73314 | XenForo before 2.3.13 contains a signature verification logic error in the PayPa | HIGH | 8.7 |
| CVE-2026-73316 | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST | HIGH | 8.7 |
| CVE-2026-74239 | XenForo before 2.3.13 contains a path traversal vulnerability in the style archi | HIGH | 8.6 |
| CVE-2026-73310 | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoin | HIGH | 8.2 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.