Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Vendors & Products |
Xenforo
Xenforo xenforo |
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread. | |
| Title | XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser | |
| Weaknesses | CWE-674 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T13:20:16.081Z
Reserved: 2026-08-11T19:56:20.008Z
Link: CVE-2026-73321
No data.
Status : Received
Published: 2026-09-08T14:17:26.617
Modified: 2026-09-08T14:17:26.617
Link: CVE-2026-73321
No data.
OpenCVE Enrichment
Updated: 2026-09-08T15:15:17Z
-
CWE-674
Uncontrolled Recursion