Back

HIGH

XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows

Published Sep 8, 2026

Description

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators that bypass forward-slash validation to write arbitrary bytes to any web-server-writable path, including the public web root, achieving persistent code execution as the web-server account.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 8, 2026
Updated Oct 1, 2026
Reserved Aug 14, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Analyzed
Modified Sep 11, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Sep 8, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-72759