CVE-2026-73312: Three OAuth2 vulnerabilities in XenForo

This text was generated using artificial intelligence (AI).XenForo released security fixes for three OAuth2 vulnerabilities in XenForo on September 8, 2026. Affected are XenForo versions prior to 2.3.13. The CVEs CVE-2026-73309, CVE-2026-73311 and CVE-2026-73312 are each with CVSS 4.0: 9.1 rated.

According to XenForo, version 2.3.13 Security fixes for the affected versions. Organizations should therefore catalog publicly accessible XenForo instances, check their patch status, and prioritize updating systems prior to 2.3.13.

Are my systems affected? Check now →