CVE-2026-35056
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-94
Source
NVD
Vendor
XenForo
Product
XenForo
Discussion (0)
Add Comment
No comments yet. Be the first!