Loading
Xenforo before 2.2.16 allows code injection.
Use CWE-94, Xenforo vendor hub and Xenforo product page to widen CVE-2024-38458 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-71279, CVE-2024-38457 and CVE-2025-71282 for nearby disclosures in the same product family.