CVE-2025-71279: XenForo Passkey Security Bypass
Published Apr 1, 2026
·Updated
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
Affected Software
2 affected components
XenForo Xenforo<2.3.7
XenForo Xenforo<2.3.7
Event History
Apr 1, 2026
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71279?
CVE-2025-71279 has a high severity due to the potential for attackers to compromise Passkey-based authentication.
2
How do I fix CVE-2025-71279?
To fix CVE-2025-71279, upgrade XenForo to version 2.3.7 or later.
3
What impact does CVE-2025-71279 have on user accounts?
CVE-2025-71279 may allow attackers to bypass security measures on user accounts using Passkeys.
4
What versions of XenForo are affected by CVE-2025-71279?
CVE-2025-71279 affects all versions of XenForo prior to 2.3.7.
5
Is there a workaround for CVE-2025-71279?
There are no recommended workarounds for CVE-2025-71279; an upgrade is necessary.