CVE-2026-73315 is an unauthenticated server-side request forgery vulnerability affecting XenForo versions before 2.3.13. The PayPal REST webhook handler processes a certificate URL supplied in webhook headers without validating its scheme or hostname and without enforcing an allowlist. A remote attacker can submit a crafted webhook POST request that causes the XenForo server to issue HTTP requests to attacker-selected destinations, including services reachable only from the server's internal network.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone Python proof of concept for CVE-2026-73315 affecting XenForo versions before 2.3.13. The repository contains a README, a Python entry point (poc.py), and a minimal Python-oriented .gitignore; it is not associated with an exploitation framework. The script constructs a synthetic PayPal PAYMENT.CAPTURE.COMPLETED JSON webhook, generates randomized event and transaction identifiers, calculates the CRC32-based signed message expected by the callback flow, and invokes the local OpenSSL binary to create an RSA/SHA-256 signature. It POSTs the callback to `/payment_callback.php?_xfProvider=paypalrest` while setting `PayPal-Cert-Url` to an operator-controlled URL. The vulnerable handler uses that header to fetch a certificate without adequately restricting the destination, enabling blind SSRF to attacker-selected HTTP(S) resources, including potentially internal or loopback services. The README notes that payment forgery is not inherently demonstrated and depends on additional target-specific webhook configuration knowledge.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated server-side request forgery vulnerability in XenForo versions before 2.3.13. A crafted certificate URL in PayPal REST webhook headers can make the server issue outbound HTTP requests to arbitrary destinations, including internal resources and cloud metadata services, potentially exposing IAM credentials or enabling secondary internal-service attacks.
An unauthenticated SSRF vulnerability in XenForo versions prior to 2.3.13's PayPal REST webhook handler. Crafted webhook headers can make the server issue outbound requests to arbitrary destinations, including internal services and cloud metadata endpoints, potentially exposing IAM credentials or facilitating secondary internal attacks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.