Loading
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
Use CWE-200, Xenforo vendor hub and Xenforo product page to widen CVE-2025-71280 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-71279, CVE-2024-38458 and CVE-2024-38457 for nearby disclosures in the same product family.