CVE-2024-25006: Xenforo

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

Affected products

  • Xenforo Xenforo: before 2.2.14 (fixed in 2.2.14)

Published 2024-02-29. Last modified 2026-06-17.