Medium severity6.1OSV Advisory· Published Aug 14, 2018· Updated Jun 17, 2026
CVE-2018-14888
CVE-2018-14888
Description
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: v1.7, v1.8, v1.9, …
- cpe:2.3:a:thank_you\/like_project:thank_you\/like:*:*:*:*:*:mybb:*:*Range: <3.1.0
- Range: <3.1.0
Patches
Vulnerability mechanics
References
4- github.com/mybbgroup/MyBB_Thank-you-like-plugin/pull/199nvdPatchThird Party Advisory
- packetstormsecurity.com/files/148871/MyBB-Thank-You-Like-3.0.0-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/45178/nvdExploitThird Party AdvisoryVDB Entry
- community.mybb.com/mods.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.