XenForo news

XenForo 2.3.13: Security Fixes and How to Update Safely

XenForo 2.3.13 fixes 14 vulnerabilities in 2.2.0 to 2.3.12. Here is who should update, what Patch 1 means for older versions, and how to update safely.

D.C Style · 7 min read
Share on X
Illustration of a server with a padlock, a wrench and an update arrow.
On this page

XenForo 2.3.13 came out on September 7, 2026, and it includes fixes for 14 security vulnerabilities. XenForo's security thread says they affect all supported versions from 2.2.0 through 2.3.12. If you run a self-hosted 2.2 or 2.3 forum and haven't updated since then, update now: to XenForo 2.3.13 if you can, or to the "Patch 1" release for your exact version if you can't.

This post sums up what XenForo published, how it fits with the September security patches, and how to update without breaking your add-ons.

XenForo 2.3.13 in short: who should update and how soon

The release and the security patches came out on the same day. They are one event, not two. The XenForo 2.3.13 announcement says the release includes the fixes from the thread "Security fixes released for all XenForo and Media Gallery versions (2.2.0 to 2.3.12)".

  • On any 2.3 version before 2.3.13: XenForo strongly recommends upgrading to 2.3.13.
  • On 2.2.x or an older 2.3.x and can't move yet: install the Patch 1 release for your version as soon as possible.
  • On XenForo Cloud: nothing to do. Cloud forums were patched earlier in a modified 2.3.11 build and stay there for now. XenForo staff said a normal bug-fix release is planned for Cloud in the near future.

XenForo's text mentions no patches for 2.1 or older.

What the XenForo 2.3.13 security fixes cover

According to the security fixes thread, the XenForo 2.3.13 security fixes resolve 14 vulnerabilities in several areas of XenForo. Depending on your version, enabled features, configuration and the attacker's privileges, the issues may allow:

  • unauthorized actions
  • disclosure of protected information
  • cross-site scripting
  • server-side requests
  • token replay
  • denial of service
  • arbitrary code execution, but only in one specific administrative workflow

All 14 findings were submitted via VulnCheck by Marco Paciaroni (BomboBombone). Neither thread gives a severity rating, CVE numbers or per-issue detail. So you can't tell from the public posts which issue matters most for your setup. That is a good reason to patch rather than guess.

Official XenForo 2.3.13 add-ons updated alongside

Three official add-ons got the 2.3.13 version number. All three need XenForo 2.3 or later.

Add-onSecurity fixes?Changed templates
Media Gallery 2.3.13Includes some of the fixestrending_content_item_xfmg_media
Resource Manager 2.3.13Not statedfeatured_content_item_resource, trending_content_item_resource, xfrm_resource_rate, xfrm_resource_reviews, xfrm_resource_updates
Enhanced Search 2.3.13Not statedNone listed

If you run Media Gallery, update it together with the core. The Media Gallery manual covers its upgrade.

The core release also has a few ordinary fixes: a workaround for a Chromium issue that applied text coloring unexpectedly, phrase development output kept during add-on data deletion, and rendered formatting kept through quoting and pasting.

Still on 2.2 or an older 2.3? Your options after the September patches

XenForo did not publish a separate manual patch. Instead, it re-released every version since 2.2.0 as a "Patch 1" build. For example, a forum on 2.2.9 can move to 2.2.9 Patch 1 without renewing its license.

XenForo's advice, in order:

  1. If you can, upgrade to 2.3.13. It has the security fixes plus the usual fixes and improvements.
  2. If you can't, install the Patch 1 release that matches your installed version, using one-click upgrade where available.

Moving from 2.2 to 2.3 is a bigger step. XenForo says 2.3 has higher system requirements than earlier versions, and your third-party add-ons each need a 2.3-ready version. Our post on add-on compatibility before moving to 2.3 walks through that. For help picking the right patch, see which XenForo security patch to install.

Before you upgrade XenForo 2.3.13: backup, versions and add-on checks

A few minutes of checks can save an evening of repairs.

  1. Back up your database and files. Make sure you know how to restore them.
  2. Check your server. The 2.3.13 post lists PHP 7.2 minimum (PHP 8.3 recommended) and MySQL 5.7 or newer, with MariaDB and Percona also compatible. Enhanced Search needs Elasticsearch 7.2 or newer.
  3. List your third-party add-ons. Check each developer's page for notes on 2.3.13. XenForo's announcement can't tell you about them.
  4. Note any custom styles. Edited copies of the changed templates will need merging afterward.
Tip:
If you have a test copy of your forum, upgrade it first. Problems show up there instead of in front of your members.

How to install 2.3.13 from the Admin CP or manually

The announcement doesn't describe any special steps for this release. XenForo recommends the one-click upgrade, which downloads and installs the new version from inside the Admin CP. XenForo's one-click upgrade help explains it.

If one-click upgrade isn't available to you, download the files from the XenForo customer area and follow the official install and upgrade manual. That manual is also the place to check for command-line upgrade steps.

Then upgrade Media Gallery, Resource Manager and Enhanced Search from the Admin CP if you use them.

After the update: merge templates, check for errors and test

A template merge combines XenForo's new version of a template with your own edits. In core, these public templates changed:

  • bb_code_tag_url_unfurl
  • featured_content_item
  • lightbox_macros
  • trending_content_item_thread

Open the outdated templates page and use the merge tool on any that appear, along with the add-on templates in the table above.

Then browse your forum as a member would. Open threads, post a reply, quote a post and check any pages your add-ons add. Look at the server error log in the Admin CP for anything new.

A good moment to tidy your crawler and traffic settings

This part isn't from XenForo's announcement. It's simply a practical habit: while you're already reviewing your forum's security, look at who is crawling it.

The manual way is to read your server access logs, spot heavy bot user agents and block them by IP or in your host's firewall. That works, but bots change IP ranges, and it's easy to block a search engine by mistake.

Our free AI Crawler Blocklist add-on (version 1.0.0, for XenForo 2.2 and later) starts in Monitor mode, so you can review AI training crawler traffic before you choose to block anything. It refreshes supported crawler IP feeds in background jobs. Google and Bing are protected through their crawler feeds and cached forward-confirmed reverse DNS, so a fake Googlebot user agent alone gets no exemption. It needs the PHP cURL extension, outbound HTTPS access to the feed providers, and XenForo scheduled jobs that run regularly. As with any new add-on, try it on a test copy first.

What to do next

  1. Check your version in the Admin CP.
  2. Back up, then upgrade to 2.3.13, or install the Patch 1 for your version.
  3. Update Media Gallery and the other official add-ons.
  4. Merge outdated templates and test your forum.

For future releases, follow our XenForo news posts.

Sources