Medium severity6.1NVD Advisory· Published Apr 4, 2026· Updated Apr 20, 2026
CVE-2018-25247
CVE-2018-25247
Description
MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profile, where liked posts are displayed without sanitization.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/45179nvdExploitVDB Entry
- www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-user-profilesnvdThird Party Advisory
- community.mybb.com/mods.phpnvdProduct
News mentions
0No linked articles in our index yet.