216.73.217.22

CVE-2025-71279

· Published 01/04/2026 01:16 · Modified 01/04/2026 18:57

Labels: CVE-2025-71279 2026-04-01CVE-2025-71279CWE-287[email protected]

Essential information

Published
01/04/2026 01:16
Modified
01/04/2026 18:57
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
xenforo / xenforo cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

References