Medium severity5.4NVD Advisory· Published Oct 26, 2021· Updated Jun 17, 2026
CVE-2021-41866
CVE-2021-41866
Description
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- MyBB/MyBBdescription
Patches
Vulnerability mechanics
References
2- github.com/mybb/mybb/security/advisories/GHSA-gxhv-r3m5-6qv7nvdPatchThird Party Advisory
- github.com/mybb/mybb/security/advisories/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.