CVE-2026-35056 - XenForo Remote Code Execution via Authenticated Admin
CVE ID :CVE-2026-35056
Published : April 1, 2026, 1:16 a.m. | 1 hour, 59 minutes ago
Description :XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 1, 2026, 1:16 a.m. | 1 hour, 59 minutes ago
Description :XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...