MEDIUMVulnerability

CVE-2026-73320

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.

Properties

severity
MEDIUM
score
6.1
cve_id
CVE-2026-73320
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
published_at
2026-09-08T14:17:26.470
last_modified
2026-09-11T20:30:06.430

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73320 — Ninja Signal Threat Intelligence | Ninja Signal