CVE-2026-73321

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-08 14:17

Updated : 2026-09-11 20:30


NVD link : CVE-2026-73321

Mitre link : CVE-2026-73321

CVE.ORG link : CVE-2026-73321


JSON object : View

Products Affected

xenforo

  • xenforo
CWE
CWE-674

Uncontrolled Recursion