216.73.216.233

CVE-2025-71282

· Published 01/04/2026 01:16 · Modified 01/04/2026 18:53

Labels: CVE-2025-71282 2026-04-01CVE-2025-71282CWE-209[email protected]

Essential information

Published
01/04/2026 01:16
Modified
01/04/2026 18:53
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
xenforo / xenforo cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

References