CVE-2026-73321: XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser

Published Sep 8, 2026
·
Updated

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.

Affected Software

1 affected component
XenForo Xenforo<2.3.13

Event History

Sep 8, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue and what access do they need?

An attacker needs an authenticated XenForo account with the ability to submit a post containing BBCode. No user interaction is required after the malicious post is submitted.

2

Which deployments are affected?

XenForo versions before 2.3.13 are affected. The issue is triggered when affected PHP-FPM workers render the thread containing the deeply nested BBCode.

3

What is the operational impact of a malicious post?

A sufficiently deeply nested BBCode post can exceed PHP's stack limit and cause fatal errors. PHP-FPM workers may repeatedly terminate for visitors rendering the affected thread, creating persistent denial of service.

4

How can administrators identify whether exploitation has occurred?

Investigate posts for unusually deep BBCode tag nesting and correlate them with PHP fatal errors or PHP-FPM worker terminations when the affected thread is rendered.

5

What should be done if immediate patching is not possible?

Remove or otherwise prevent rendering of posts containing deeply nested BBCode tags, particularly in threads associated with PHP fatal errors or PHP-FPM worker crashes. Upgrade to XenForo 2.3.13 when possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203