CVE-2025-71282: XenForo Path Disclosure via open_basedir Exceptions
Published Apr 1, 2026
·Updated
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by openbasedir restrictions. This allows an attacker to obtain information about the server's directory structure.
Affected Software
2 affected components
XenForo Xenforo<2.3.7
XenForo Xenforo<2.3.7
Event History
Apr 1, 2026
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71282?
CVE-2025-71282 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-71282?
To fix CVE-2025-71282, upgrade XenForo to version 2.3.7 or later.
3
What are the risks associated with CVE-2025-71282?
The risks of CVE-2025-71282 include the potential exposure of sensitive filesystem paths, which could aid attackers in further exploiting the server.
4
Which versions of XenForo are affected by CVE-2025-71282?
CVE-2025-71282 affects all versions of XenForo prior to 2.3.7.
5
Is there a workaround for CVE-2025-71282 if I can't upgrade?
A potential workaround for CVE-2025-71282 is to ensure open_basedir restrictions are properly configured to limit access to system directories.