Releases XenForo 2.3.9 (inc XFMG) & 2.2.18 Released (Security Fix)

Compatible XF Versions
2.3
  • Thread starter
  • Admin

XenForo 2.3.9 Released​

Today we are releasing XenForo 2.3.9 to address some potential security vulnerabilities that were recently reported to us. This version only includes security fixes and any bug fixes we previously said would make it to 2.3.9 have now been delayed until 2.3.10.

It is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.3 upgrade to this release to benefit from increased stability.

The issues identified are as follows:
  • Prevention of a possible stored XSS (cross-site scripting) exploit related to BB code rendering (thank you to Antisocial)
  • Prevention of a possible XSS exploit related to lightbox usage in posts (thank you UwU)
  • Prevention of a possible RCE (remote code execution) exploit via authenticated, but malicious, admin users (thank you UwU)
If you are a XenForo Cloud customer, fixes for these issues have been rolled out automatically, and no further action is required to address them.

We recommend doing a full upgrade to resolve the issue, but a patch can be applied manually. See below for further details.

Upload patch files​

  • Download 239-patch.zip
  • Extract the .zip file
  • Upload the contents of the upload directory to the root of your XenForo installation
  • Rebuild master data by logging in to your install URL, or running xf:rebuild-master-data on the command line
Note: If you decide to patch the files instead of doing full upgrades, your "File health check" will report these files as having "Unexpected contents". Because these files no longer contain the same contents your version of XF was shipped with, this is expected and can be safely ignored.

If you are a XenForo Cloud customer, your installations have already been patched and no further action is required. You will remain on version 2.3.8 until 2.3.10 is released.
1752677565835-png.16810

The following public templates have had changes:
  • attachment_macros
  • bb_code_tag_attach
  • lightbox_macros
Where necessary, the merge system within the "outdated templates" page should be used to integrate these changes.
 

Attachments

  • 239-patch.zip
    573.6 KB · Views: 0

TEHRAN

Supervisor
  • Thread starter
  • Admin
  • #2

XenForo 2.2.18 Released​


XenForo 2.2.18 has also been released. Please refer to the release notes above. Only two of the three security issues apply to XenForo 2.2.18. The stored XSS is not applicable.

We recommend doing a full upgrade to resolve the issue, but a patch can be applied manually. See below for further details.
  • Download 2218-patch.zip
  • Extract the .zip file
  • Upload the contents of the upload directory to the root of your XenForo installation
Note: If you decide to patch the files instead of doing full upgrades, your "File health check" will report these files as having "Unexpected contents". Because these files no longer contain the same contents your version of XF was shipped with, this is expected and can be safely ignored.
 

Attachments

  • 2218-patch.zip
    576.4 KB · Views: 0

TEHRAN

Supervisor
  • Thread starter
  • Admin
  • #3

2.3.9 patch files for pre-XF 2.3.8 installs​

Some users may struggle to apply the patch on pre-2.3.8 installs. If you are patching 2.3.7 or earlier you may try this patch.
 

Attachments

  • 239-patch-pre238.zip
    563.3 KB · Views: 0
Back
Top Bottom