Home / CVEs we hold for Xen CVEs we hold for Xen Records whose assigning authority named Xen as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-79603 Unconditionally do TLB flushing ahead of page scrubbing Xen CVE-2026-74239 XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows XenForo CVE-2026-73321 XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser XenForo CVE-2026-73320 XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint XenForo CVE-2026-73319 XenForo < 2.3.13 XSS via Dynamic Redirect Handler XenForo CVE-2026-73318 XenForo < 2.3.13 Missing Authorization via force-agreement Controller XenForo CVE-2026-73317 XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher XenForo CVE-2026-73316 XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider XenForo CVE-2026-73315 XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler XenForo CVE-2026-73314 XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook XenForo CVE-2026-73313 XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider XenForo CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token XenForo CVE-2026-73310 XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass XenForo CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint XenForo CVE-2026-66473 WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability Xendit Payment CVE-2026-62436 grant-table: version change racing with other operations Xen CVE-2026-62435 grant-table: version change racing with other operations Xen CVE-2026-4075 BWL Advanced FAQ Manager Lite <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sbox_id'… xenioushk BWL Advanced FAQ Manager Lite CVE-2026-35174 Chyrp Lite has a Path Traversal to Remote Code Execution xenocrat chyrp-lite CVE-2026-35173 Chyrp Lite has an IDOR via Mass Assignment in Post Model xenocrat chyrp-lite CVE-2026-35057 XenForo Stored Cross-Site Scripting via Structured Text Mentions XenForo CVE-2026-35056 XenForo Remote Code Execution via Authenticated Admin XenForo CVE-2026-35055 XenForo Cross-Site Scripting via Lightbox in Posts XenForo CVE-2026-35054 XenForo Stored Cross-Site Scripting via BB Code Rendering XenForo CVE-2026-23556 oxenstored keeps quota related use counts across domain destruction Xen oxenstored CVE-2025-71282 XenForo Path Disclosure via open_basedir Exceptions XenForo CVE-2025-71280 XenForo Local Account Page Caching Information Disclosure XenForo CVE-2025-68992 WordPress BWL Knowledge Base Manager plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability xenioushk BWL Knowledge Base Manager CVE-2025-68991 WordPress BWL Pro Voting Manager plugin <= 1.4.9 - Cross Site Scripting (XSS) vulnerability xenioushk BWL Pro Voting Manager CVE-2025-68990 WordPress BWL Pro Voting Manager plugin <= 1.4.9 - SQL Injection vulnerability xenioushk BWL Pro Voting Manager CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory Xen varstored CVE-2025-58149 Incorrect removal of permissions on PCI device unplug Xen CVE-2025-58148 x86: Incorrect input sanitisation in Viridian hypercalls Xen CVE-2025-58147 x86: Incorrect input sanitisation in Viridian hypercalls Xen CVE-2025-27465 x86: Incorrect stubs exception handling for flags recovery Xen CVE-2025-27464 WinPVDrivers: Excessive permissions on user-exposed devices Xen Windows PV drivers CVE-2025-27463 WinPVDrivers: Excessive permissions on user-exposed devices Xen Windows PV drivers CVE-2025-27462 WinPVDrivers: Excessive permissions on user-exposed devices Xen Windows PV drivers CVE-2025-1713 deadlock potential with VT-d and legacy PCI device pass-through Xen CVE-2024-32136 WordPress BWL Advanced FAQ Manager plugin <= 2.0.3 - Auth. SQL Injection vulnerability Xenioushk BWL Advanced FAQ Manager CVE-2024-31144 Xapi: Metadata injection attack against backup/restore functionality Xen CVE-2024-13801 BWL Advanced FAQ Manager <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options… xenioushk BWL Advanced FAQ Manager CVE-2023-53904 Xenforo 2.2.13 Authenticated Stored Cross-Site Scripting via Smilie Categories Xenforo CVE-2023-46839 pci: phantom functions assigned to incorrect contexts Xen CVE-2023-46837 arm32: The cache may not be properly cleaned/invalidated (take two) Xen CVE-2023-46835 x86/AMD: mismatch in IOMMU quarantine page table levels Xen CVE-2023-34323 xenstored: A transaction conflict can crash C Xenstored Xen CVE-2023-34322 top-level shadow reference dropped too early for 64-bit PV guests Xen CVE-2023-34321 arm32: The cache may not be properly cleaned/invalidated Xen CVE-2009-20003 Xenorate <= 2.50 .xpl File Stack-Based Buffer Overflow Xenorate 175 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.