CVE-2026-73314Xenforo · Xenforo
Vulnerability data via NVD (ingested)
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing the caller to treat the fabricated request as verified and process the payment event without a valid PayPal signature.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-73314product:"Xenforo Xenforo"http.html:"Xenforo"More intel sources (5)
vuln:CVE-2026-73314vulnerabilities.cve_id: CVE-2026-73314CVE-2026-73314CVE-2026-73314"CVE-2026-73314" exploit -site:nvd.nist.gov