Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Vendors & Products |
Xenforo
Xenforo xenforo |
Tue, 08 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows. | |
| Title | XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T13:46:11.329Z
Reserved: 2026-08-11T19:56:20.007Z
Link: CVE-2026-73310
Updated: 2026-09-08T13:45:57.998Z
Status : Awaiting Analysis
Published: 2026-09-08T14:17:25.073
Modified: 2026-09-08T19:54:50.793
Link: CVE-2026-73310
No data.
OpenCVE Enrichment
Updated: 2026-09-08T16:15:15Z
-
CWE-863
Incorrect Authorization