CVE-2025-71281 | XenForo up to 2.3.6 code injection
A vulnerability described as critical has been identified in XenForo up to 2.3.6. This issue affects some unknown processing. The manipulation results in code injection.
This vulnerability is cataloged as CVE-2025-71281. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.