VYPR

Mybb

by MyBB

Source repositories

CVEs (201)

  • CVE-2026-45121MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected calendar-selection paths in…

  • CVE-2026-45120MedAug 18, 2026
    risk 0.28cvss 5.4epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The private-event check used by get_events() in…

  • CVE-2018-1000503MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view posts from private forums without having the password. This attack appear to be exploitable via Subscribe to a forum through IDOR. This vulnerability appears to…

  • CVE-2026-46482MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value. [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:…

  • CVE-2026-45734MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass CAPTCHA controls through challenge replay. The successful validation paths in contact.php,…

  • CVE-2026-45125MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the stored username for…

  • CVE-2026-45129MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Admin CP Home, Preferences,…

  • CVE-2026-45119MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially crafted URL. The do=all control flow in…

  • CVE-2026-47245MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate reciprocal buddy-list updates correctly. The usercp.php?action=do_editlists delete handler removes the selected entry from the acting user's list and then…

  • CVE-2026-45124MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is…

  • CVE-2026-45123MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in…

  • CVE-2026-45122MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user…

  • CVE-2026-45128LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a specially crafted URL. The Set as Default…

  • CVE-2026-45127LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially crafted URL. The Resend route in Admin CP,…

  • CVE-2026-45126LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with a specially crafted URL. The controller…

  • CVE-2008-0382Jan 22, 2008
    risk 0.06cvss —epss 0.42

    Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

  • CVE-2014-9241Dec 3, 2014
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to usercp.php, or (3) title…

  • CVE-2014-9240Dec 3, 2014
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.

  • CVE-2012-5909Nov 17, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.

  • CVE-2012-5908Nov 17, 2012
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.

Page 5 of 11