GHSA-vv8x-44ww-j3whHighCVSS 6.5

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that...

Published
September 8, 2026
Last Modified
September 9, 2026

🔗 CVE IDs covered (1)

📋 Description

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craft a single malicious post with sufficient nesting depth to exceed PHP's stack limit, causing fatal errors that repeatedly terminate PHP-FPM workers for all visitors rendering the affected thread.

🔗 References (7)