Back to CVE List

CVE-2026-35056

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-94
Source
NVD
Vendor
XenForo
Product
XenForo

External References

Discussion (0)

Add Comment

No comments yet. Be the first!