Mybb
by MyBB
Source repositories
CVEs (183)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43708 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2022 | MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name | ||
| CVE-2022-43707 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2022 | MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data | ||
| CVE-2021-27949 | Med | 0.40 | 6.1 | 0.01 | Mar 15, 2021 | Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools. | ||
| CVE-2019-20225 | Med | 0.40 | 6.1 | 0.01 | Jan 2, 2020 | MyBB before 1.8.22 allows an open redirect on login. | ||
| CVE-2019-3578 | Med | 0.40 | 6.1 | 0.01 | Jun 6, 2019 | MyBB 1.8.19 has XSS in the resetpassword function. | ||
| CVE-2018-19202 | Med | 0.40 | 6.1 | 0.01 | Apr 11, 2019 | A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter. | ||
| CVE-2018-19201 | Med | 0.40 | 6.1 | 0.01 | Mar 29, 2019 | A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter. | ||
| CVE-2018-10678 | Med | 0.40 | 6.1 | 0.01 | May 13, 2018 | MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks. | ||
| CVE-2017-8103 | Med | 0.40 | 6.1 | 0.01 | Apr 24, 2017 | In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event. | ||
| CVE-2016-9421 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9419 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9409 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs. | ||
| CVE-2016-9408 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users. | ||
| CVE-2016-9407 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs. | ||
| CVE-2016-9406 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9405 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9404 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login. | ||
| CVE-2015-8976 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files." | ||
| CVE-2015-8975 | Med | 0.40 | 6.1 | 0.02 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2017-16781 | Med | 0.38 | 5.4 | 0.02 | Nov 10, 2017 | The installer in MyBB before 1.8.13 has XSS. |
- risk 0.40cvss 6.1epss 0.00
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
- risk 0.40cvss 6.1epss 0.00
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data
- risk 0.40cvss 6.1epss 0.01
Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
- risk 0.40cvss 6.1epss 0.01
MyBB before 1.8.22 allows an open redirect on login.
- risk 0.40cvss 6.1epss 0.01
MyBB 1.8.19 has XSS in the resetpassword function.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.
- risk 0.40cvss 6.1epss 0.01
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
- risk 0.40cvss 6.1epss 0.01
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.38cvss 5.4epss 0.02
The installer in MyBB before 1.8.13 has XSS.
Page 3 of 10