MEDIUM 5.1 NVD
CVE-2026-73319
XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary J
XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.
Affected Products
- xenforo/xenforo
References
- https://bombobombone.github.io/posts/cve-2026-73319/
- https://github.com/BomboBombone/CVE-2026-73319
- https://www.vulncheck.com/advisories/xenforo-xss-via-dynamic-redirect-handler
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-ga
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-securit
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-09-08 via NVD. Affected: xenforo/xenforo.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.