Loading
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.
Cite this page
CVE-2025-71278. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-71278
Use CWE-863, Xenforo vendor hub and Xenforo product page to widen CVE-2025-71278 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-71279, CVE-2024-38458 and CVE-2024-38457 for nearby disclosures in the same product family.