CVE-2026-73320
Last modified
CVE-2026-73320 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xenforo | Xenforo | < 2.3.13 |
References
- https://bombobombone.github.io/posts/cve-2026-73320/Exploit, Third Party Advisory
- https://github.com/BomboBombone/CVE-2026-73320Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-73320?
How severe is CVE-2026-73320?
How do I fix CVE-2026-73320?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73315XenForo before 2.3.13 contains a server-side request forgery…8.6
- CVE-2026-73316XenForo before 2.3.13 contains a payment replay vulnerabilit…7.5
- CVE-2026-73317XenForo before 2.3.13 contains a missing authorization vulne…2.7
- CVE-2026-73318XenForo before 2.3.13 contains a missing authorization vulne…3.8
- CVE-2026-73319XenForo before 2.3.13 contains a cross-site scripting vulner…6.1
- CVE-2026-7332The LatePoint – Calendar Booking Plugin for Appointments and…7.2
- CVE-2026-73321XenForo before 2.3.13 contains an uncontrolled recursion vul…6.5
- CVE-2026-73323Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73324Certain VLC media player builds in versions 3.0.0 through 3.…4.3
- CVE-2026-73325Fujitsu Research's OneCompression library before 1.2.1 conta…7.8
- CVE-2026-73326CamaleonCMS contains a missing authorization vulnerability t…7.6
- CVE-2026-73327Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-73320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
