CVE-2026-73319: XenForo < 2.3.13 XSS via Dynamic Redirect Handler

Published Sep 8, 2026
·
Updated

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.

Affected Software

1 affected component
XenForo Xenforo<2.3.13

Event History

Sep 8, 2026
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

XenForo versions before 2.3.13 are affected. The issue is in the dynamic redirect handler.

2

What must an attacker do to exploit this?

An unauthenticated attacker must craft a malicious javascript: URI that embeds the board hostname in its authority component and uses percent-encoded newlines to bypass server-side filters. An authenticated user must then perform a Follow action using the attacker-controlled link or content.

3

What is the impact if exploitation succeeds?

Attacker-supplied JavaScript executes in the affected board's origin in the authenticated victim's browser. This can expose information available to that user and allow actions with that user's browser session context.

4

What version addresses the issue?

Upgrade XenForo to version 2.3.13 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203