XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users. | |
| Title | XenForo Local Account Page Caching Information Disclosure | |
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xenforo
Xenforo xenforo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T01:43:20.759Z
Reserved: 2026-04-01T00:19:58.851Z
Link: CVE-2025-71280
No data.
Status : Received
Published: 2026-04-01T01:16:40.393
Modified: 2026-04-01T01:16:40.393
Link: CVE-2025-71280
No data.
OpenCVE Enrichment
No data.
Weaknesses