Medium severity4.8OSV Advisory· Published Jan 2, 2019· Updated Jun 17, 2026
CVE-2019-3501
CVE-2019-3501
Description
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 1.1, 1.8.0, 1.8.3, …
- cpe:2.3:a:ougc_awards_project:ougc_awards:*:*:*:*:*:mybb:*:*Range: <1.8.19
- Range: <1.8.19
- Range: <1.8.19
Patches
Vulnerability mechanics
References
3- github.com/Sama34/OUGC-Awards/issues/29nvdExploitIssue TrackingThird Party Advisory
- github.com/Sama34/OUGC-Awards/pull/31nvdThird Party Advisory
- www.exploit-db.com/exploits/46080/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.