Forum Is getting hacked [Big Thread]

src="..."
YES LITTERALY

some media fetch the real website and other use an html and the URL in the whole payload

if you control the Url you can contrôle the payload

and maybe add a second src or remove the first one

I was able to do it I think but It exposes the person who does it
 
Last edited:
I used a different email proton mail to sign up w opsec :p
 
  • +1
  • Hmm...
Reactions: Romxnus753AC and shedontluv-U
YES LITTERALY

some media fetch the real website and other use an html and the URL in the whole payload

if you control the Url you can contrôle the payload

and maybe add a second src or remove the first one

I was able to do it I think but It exposes the person who does it
CSP still stops it from firing, and the URL is logged everywhere. That's why the only clean move is a DM to staff but staff here does nothing
 
  • +1
Reactions: shedontluv-U
so what does this mean?

Feds can see my info
 
  • JFL
Reactions: shedontluv-U
so what does this mean?

Feds can see my info
They always did but this is about if ur lm.org account gets to see another day (if someone does something)
 
  • +1
Reactions: TGUN.
so what does this mean?

Feds can see my info
Feds can always see your info thomas

don't be afraid it's already over

It's been years
 
  • JFL
Reactions: TGUN.
so what does this mean?

Feds can see my info

yea but I was trying to make a botb with that

and I was going to report all the vulnerability to admin ( not the formatting one )
keep it for yourself Any template-based media embed that lets you break attribute quoting is a real bug, DM it to staff with the exact tag and URL don't thread it. Credit without exposure.
 
  • +1
Reactions: shedontluv-U
They always did but this is about if ur lm.org account gets to see another day (if someone does something)
So someone can just delete my account?
 
  • JFL
Reactions: shedontluv-U
(@
Master
@Master i can help y fix all of this, just delete my old cringe posts and ill do it for free, i dont wanna force my way into doing this without auth cuz yk its illigal)
op breached the forum to delete some of his cringe threads JFL

jbv

Just buy Vip bro
 
So someone can just delete my account?
Thats if they hack master account which is exposed like all of our account BECAUSE @Master WONT UPDATE THE SOFTWARE THIS SITE WAS BUILT ON
 
  • +1
  • JFL
Reactions: shedontluv-U and TGUN.
Thats if they hack master account which is exposed like all of our account BECAUSE @Master WONT UPDATE THE SOFTWARE THIS SITE WAS BUILT ON
org is still on PHP ? or sum shit like that ??

Xenforo is pretty secure from what I saw
 
How am I going to be able to make interactive threads then?

huh ??? :p

Php is not the issue

XenForo's the issue, not PHP.

MFA bypass in the passkey provider (CVE-2026-73313): global credential lookup, no check that the passkey belongs to the logging-in user. Know the password, sign the challenge with your own key, second factor done. Forum and ACP both.

OAuth2 code reuse (73311) and refresh token replay (73312): codes aren't invalidated after exchange, refresh tokens aren't consumed when the parent expires. Replay for days.

Stored XSS via BB code pre-2.3.9 (35054). SSRF in the PayPal webhook cert URL (73315).

All patched in 2.3.13, September 2026. If the backend isn't there yet, that's the whole attack surface. Tell @Master to push the update.
 
  • +1
Reactions: shedontluv-U
can you help me tho :feelspepo:

like find a way to make media interactive without exposing anyone?
 
Oh no:ROFLMAO::ROFLMAO::ROFLMAO::ROFLMAO:
 
  • Hmm...
  • +1
  • JFL
Reactions: ReccesedSlavic, Romxnus753AC and shedontluv-U
XenForo's the issue, not PHP.

MFA bypass in the passkey provider (CVE-2026-73313): global credential lookup, no check that the passkey belongs to the logging-in user. Know the password, sign the challenge with your own key, second factor done. Forum and ACP both.

OAuth2 code reuse (73311) and refresh token replay (73312): codes aren't invalidated after exchange, refresh tokens aren't consumed when the parent expires. Replay for days.

Stored XSS via BB code pre-2.3.9 (35054). SSRF in the PayPal webhook cert URL (73315).

All patched in 2.3.13, September 2026. If the backend isn't there yet, that's the whole attack surface. Tell @Master to push the update.
give me a fucking exemple how the fuck

you can inject shit in the bbcode parser ?

you can make randomized attributs or use your own script

only ways oembed but guess what ??
disable bro :soy::soy::soy::soy::soy::soy::soy::soy::soy::soy::soy:
 
Bros not even using a vpn:ROFLMAO: hack this forum and I come to your house:ROFLMAO::ROFLMAO::ROFLMAO:
 
  • JFL
  • +1
  • Ugh..
Reactions: Romxnus753AC, pleasevanity and ReccesedSlavic
Holy bro got banned
 
  • WTF
  • Hmm...
Reactions: Romxnus753AC and shedontluv-U
1000025391


Oh My God Reaction GIF


they killed encryption bro 😭
 
  • WTF
Reactions: Romxnus753AC
dude just got banned 👀
 
  • JFL
Reactions: shedontluv-U
View attachment 5707838

@Master


I've been digging into the recent incidents and some of you need to hear this, because I don't think people realize how exposed we are right now.

First: this isn't just about stolen passwords.

Yes, the stealer logs are real. Yes, accounts are getting taken over. But there's a second problem nobody's talking about: the forum software itself has known vulnerabilities that were only patched in September 2026.

We're running XenForo. If the backend hasn't been updated to 2.3.13, we're sitting on at least a dozen documented CVEs. Here are the ones that matter:

OAuth2 authorization code reuse (CVE-2026-73311) — XenForo before 2.3.13 fails to invalidate authorization codes after use. An attacker who intercepts a code can replay it multiple times to generate token pairs for someone else's account. This bypasses the single-use guarantee that OAuth2 is supposed to provide.

OAuth2 refresh token replay (CVE-2026-73312) — Related issue. Refresh tokens aren't marked as consumed when the parent access token expires. An attacker can repeatedly submit the same refresh token to generate unlimited new token pairs, maintaining persistent access to the victim's account for the token's full lifetime.

Passkey MFA bypass (CVE-2026-73313) — This one is brutal. The passkey TFA provider performs a global credential lookup without verifying that the matched credential actually belongs to the user logging in. An attacker who knows a target's password can complete the target's two-step login using their own passkey. Affects both public forum login and ACP admin login. Reproduced on 2.3.12 (build 2031270).

Stored XSS via BB code (CVE-2026-35054) — XenForo before 2.3.9. Malicious scripts injected through BB code rendering get stored and executed when other users view the content. CVSS 6.4. This is how you get session hijacking en masse.

Missing authorization in force-agreement controller (CVE-2026-73318) — XenForo before 2.3.13. Any ACP administrator, regardless of assigned permissions, can access and submit force-agreement forms, forcing all users to re-agree to privacy policy or ToS. Low severity individually, but it shows the authorization model is broken in places.

There are more. Path traversal in the style archive importer on Windows deployments. SSRF in 2.3.8. Unfurl endpoint information disclosure. BBCode parser recursion. The full patch list for 2.3.13 covers 14 vulnerabilities reported by VulnCheck.

Why this matters right now

If the forum hasn't been updated past 2.3.12, every one of these is a potential entry point. Combined with the stealer logs, you have a situation where:

Accounts are being compromised via stolen credentials

The software has documented auth bypass and token replay flaws that make sessions harder to revoke

MFA — the thing we're all told to enable — can be bypassed if the backend isn't patched

What you should do

Enable 2FA anyway. It's still better than nothing, and it stops the low-effort attacks.

Don't reuse passwords. If your email is in a stealer log, your forum account is next.

If you're staff or have ACP access: verify the backend is on 2.3.13 or later. There's no reason to be on an older build.

If you're a regular user: you can't patch the server, but you can reduce your exposure. Check haveibeenpwned.com. Change your password if it's ever been used elsewhere.

The bottom line

We're not just dealing with compromised accounts. We're dealing with a forum running software that has known, documented, remotely exploitable authentication flaws. If nothing gets patched, the next wave won't need stolen passwords. It'll just walk through the front door.

I'm not trying to fearmonger. I'm saying: check the version. Patch the server. Enable 2FA. Do it now.

(@Master i can help y fix all of this, just delete my old cringe posts and ill do it for free, i dont wanna force my way into doing this without auth cuz yk its illigal)
not to mention the admin panel's directory isn't randomized
 
I spent fucking WEEKS finding way or tricks to bypass org formating limitations just for one thread :lasereyes:

And you you find as that much?
he's just assuming the forum is not updated to the current version and going off an exploit directory, I would think a forum this large would have an auto update features so these exploits might be useless
 

Similar threads

Mai Sakurajima.
Replies
4
Views
35
Mai Sakurajima.
Mai Sakurajima.
dhusc
Replies
7
Views
70
ToDelirium
ToDelirium
TGUN.
Replies
52
Views
328
sonic55555
S

Users who are viewing this thread

  • Back
    Top