Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users. | |
| Title | XenForo Local Account Page Caching Information Disclosure | |
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xenforo
Xenforo xenforo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T13:20:08.426Z
Reserved: 2026-04-01T00:19:58.851Z
Link: CVE-2025-71280
Updated: 2026-04-01T13:20:01.442Z
Status : Analyzed
Published: 2026-04-01T01:16:40.393
Modified: 2026-04-01T18:52:12.647
Link: CVE-2025-71280
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:09:45Z