CVE-2025-71280 | XenForo up to 2.3.6 User Information information disclosure
A vulnerability classified as problematic was found in XenForo up to 2.3.6. The affected element is an unknown function of the component User Information Handler. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2025-71280. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is advised.