Cloudflare blocking Xenforo messages containing "cmd.exe"

I have an app named “tcmd.exe”; when including that name or a link to my website to download the file, I get an “Oops!” popup trying to post the message.

I assume this is a security check for “cmd.exe”, but it’s making it really difficult for me (or my users) to post messages. XenForo says that Cloudflare is blocking the messages; the browser console seems to confirm this.

I can’t find the appropriate Cloudflare ruleset to block.

You should be able to search by rayID in your security events to see the ruleID that is blocking these requests.

You can then search by that rule ID in the ruleset section of your WAF.

This is more than likely a Command Injection WAF rule.

