CVE-2026-51833
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
17/07/2026
Last modified:
23/07/2026
Description
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



