VYPR

Mybb

by MyBB

Source repositories

CVEs (201)

  • CVE-2025-29459HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2025-29458HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2025-29457HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2022-24734HigMar 9, 2022
    risk 0.49cvss 7.2epss 0.78

    MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change…

  • CVE-2016-9418HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.

  • CVE-2016-9415HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."

  • CVE-2016-9414HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missing directory listing protection in upload directories.

  • CVE-2016-9410HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via vectors involving templates.

  • CVE-2015-8977HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.

  • CVE-2008-4929HigNov 4, 2008
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.

  • CVE-2016-9417HigJan 31, 2017
    risk 0.48cvss 7.4epss 0.01

    The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

  • CVE-2022-45867HigJan 3, 2023
    risk 0.47cvss 7.2epss 0.01

    MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.

  • CVE-2021-43281HigNov 4, 2021
    risk 0.47cvss 7.2epss 0.01

    MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type "php" with…

  • CVE-2021-27948HigMar 15, 2021
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).

  • CVE-2021-27947HigMar 15, 2021
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).

  • CVE-2019-12831HigJun 15, 2019
    risk 0.47cvss 7.2epss 0.01

    In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by…

  • CVE-2018-1000502HigJun 26, 2018
    risk 0.47cvss 7.2epss 0.01

    MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance -> Task Manager -> Add New Task) that can result in Allows Local File Inclusion on modern PHP versions and Remote File Inclusion on ancient PHP versions. This attack appear to be…

  • CVE-2018-17128MedSep 17, 2018
    risk 0.44cvss 5.4epss 0.49

    A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.

  • CVE-2021-27889MedMar 15, 2021
    risk 0.43cvss 6.1epss 0.05

    Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.

  • CVE-2018-15596MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.03

    An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't…

Page 2 of 11