Vulnerability Description
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/dennywise/CVE-2026-51833-Public-Disclosure/blob/main/CVE-2026
- https://xenforo.com
- https://github.com/dennywise/CVE-2026-51833-Public-Disclosure/blob/main/CVE-2026
FAQ
What is CVE-2026-51833?
CVE-2026-51833 is a vulnerability with a CVSS score of 7.5 (HIGH). Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the ser...
How severe is CVE-2026-51833?
CVE-2026-51833 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-51833?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.