CVE-2026-73315 | XenForo up to 2.3.12 PayPal REST Webhook server-side request forgery

SecurityVulns

A vulnerability classified as critical has been found in XenForo up to 2.3.12. This affects an unknown function of the component PayPal REST Webhook Handler. Performing a manipulation results in server-side request forgery.

This vulnerability is known as CVE-2026-73315. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More