Loading
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
Use CWE-22, Xenforo vendor hub and Xenforo product page to widen CVE-2024-25006 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-71279, CVE-2024-38458 and CVE-2024-38457 for nearby disclosures in the same product family.