CVE-2026-73315
Analyzed Analyzed - Analysis Complete

Server-Side Request Forgery in XenForo PayPal Webhook Handler

Vulnerability report for CVE-2026-73315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulnCheck

Description

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xenforo xenforo to 2.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-73315 is a Server-Side Request Forgery (SSRF) vulnerability in XenForo versions before 2.3.13. It affects the PayPal REST webhook handler where unauthenticated attackers can manipulate the PAYPAL-CERT-URL header to point to arbitrary destinations without proper validation. This allows the server to make outbound HTTP requests to internal or external resources, potentially exposing sensitive data or enabling further attacks.

Detection Guidance

To detect this vulnerability, monitor outbound HTTP/HTTPS requests from your XenForo server, particularly those originating from the PayPal webhook handler. Check for unexpected connections to internal or external IP addresses, especially loopback or cloud metadata endpoints. Review server logs for POST requests to /paypal-webhook or similar endpoints with PAYPAL-CERT-URL headers pointing to unusual destinations.

Impact Analysis

This vulnerability could allow attackers to force your XenForo server to make requests to internal systems, such as cloud metadata services, potentially stealing IAM credentials or accessing sensitive internal services. While full payment forgery requires additional factors, the risk of unauthorized server-side requests and data exposure is significant.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Exposure of IAM credentials or internal service access may result in compliance breaches, fines, or reputational damage.

Mitigation Strategies

Immediately upgrade XenForo to version 2.3.13 or later to patch the SSRF vulnerability. If upgrading is not possible, restrict outbound network access from the XenForo server using firewall rules to block unauthorized connections. Disable or closely monitor the PayPal webhook handler until patched. Review and validate all webhook headers and certificate URLs in your PayPal integration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart