CVE-2026-73315Xenforo · Xenforo
Vulnerability data via NVD (ingested)
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-73315product:"Xenforo Xenforo"http.html:"Xenforo"More intel sources (5)
vuln:CVE-2026-73315vulnerabilities.cve_id: CVE-2026-73315CVE-2026-73315CVE-2026-73315"CVE-2026-73315" exploit -site:nvd.nist.gov