CRITICAL 9.1 NVD

CVE-2026-73312

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to m

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.

Affected Products

References

Published: 2026-09-08 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-08 via NVD. Affected: xenforo/xenforo.

Risk Timeline

CVE Disclosed2026-09-08 · 2 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-73309XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuCRITICAL9.1
CVE-2026-73311XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability CRITICAL9.1
CVE-2026-73314XenForo before 2.3.13 contains a signature verification logic error in the PayPaHIGH8.7
CVE-2026-73316XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal RESTHIGH8.7
CVE-2026-74239XenForo before 2.3.13 contains a path traversal vulnerability in the style archiHIGH8.6
CVE-2026-73310XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoinHIGH8.2
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.