← back
CVE-2026-73312criticalCWE-294

XenForo < 2.3.13 Refresh Token Replay via Expired Access Token

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.1epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
XenForo · XenForo
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.