Mybb
by MyBB
Source repositories
CVEs (183)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23335 | Med | 0.00 | 4.7 | 0.01 | May 1, 2024 | MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolves this issue. Users are… | ||
| CVE-2023-46251 | Hig | 0.00 | 7.5 | 0.00 | Nov 6, 2023 | MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual… | ||
| CVE-2023-41362 | Hig | 0.00 | 7.2 | 0.02 | Aug 29, 2023 | MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP. | ||
| CVE-2022-39265 | Hig | 0.00 | 7.2 | 0.02 | Oct 6, 2022 | MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remote Code… | ||
| CVE-2021-27279 | Med | 0.00 | 5.4 | 0.01 | Feb 22, 2021 | MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode). | ||
| CVE-2020-15139 | Hig | 0.00 | 8.8 | 0.01 | Aug 10, 2020 | In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as… | ||
| CVE-2015-4552 | 0.00 | — | 0.02 | Sep 3, 2015 | Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post. | |||
| CVE-2015-2786 | 0.00 | — | 0.01 | Mar 29, 2015 | Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders." | |||
| CVE-2015-2352 | 0.00 | — | 0.01 | Mar 19, 2015 | The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors. | |||
| CVE-2015-2335 | 0.00 | — | 0.01 | Mar 18, 2015 | A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors. | |||
| CVE-2015-2334 | 0.00 | — | 0.01 | Mar 18, 2015 | Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |||
| CVE-2015-2333 | 0.00 | — | 0.01 | Mar 18, 2015 | Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2015-2332 | 0.00 | — | 0.01 | Mar 18, 2015 | Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2015-2149 | 0.00 | — | 0.02 | Mar 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types module… | |||
| CVE-2014-5248 | 0.00 | — | 0.01 | Aug 14, 2014 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode. | |||
| CVE-2014-1840 | 0.00 | — | 0.01 | Mar 3, 2014 | Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message. | |||
| CVE-2013-7288 | 0.00 | — | 0.01 | Jan 10, 2014 | Cross-site scripting (XSS) vulnerability in the mycode_parse_video function in inc/class_parser.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via vectors related to Yahoo video URLs. | |||
| CVE-2013-7275 | 0.00 | — | 0.02 | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup. | |||
| CVE-2011-5133 | 0.00 | — | 0.02 | Aug 30, 2012 | Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list." | |||
| CVE-2011-5132 | 0.00 | — | 0.01 | Aug 30, 2012 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX." |
- risk 0.00cvss 4.7epss 0.01
MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolves this issue. Users are…
- risk 0.00cvss 7.5epss 0.00
MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual…
- risk 0.00cvss 7.2epss 0.02
MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.
- risk 0.00cvss 7.2epss 0.02
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remote Code…
- risk 0.00cvss 5.4epss 0.01
MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
- risk 0.00cvss 8.8epss 0.01
In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as…
- CVE-2015-4552Sep 3, 2015risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.
- CVE-2015-2786Mar 29, 2015risk 0.00cvss —epss 0.01
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."
- CVE-2015-2352Mar 19, 2015risk 0.00cvss —epss 0.01
The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.
- CVE-2015-2335Mar 18, 2015risk 0.00cvss —epss 0.01
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.
- CVE-2015-2334Mar 18, 2015risk 0.00cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2015-2333Mar 18, 2015risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2015-2332Mar 18, 2015risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2015-2149Mar 18, 2015risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types module…
- CVE-2014-5248Aug 14, 2014risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.
- CVE-2014-1840Mar 3, 2014risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.
- CVE-2013-7288Jan 10, 2014risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the mycode_parse_video function in inc/class_parser.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via vectors related to Yahoo video URLs.
- CVE-2013-7275Jan 8, 2014risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup.
- CVE-2011-5133Aug 30, 2012risk 0.00cvss —epss 0.02
Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."
- CVE-2011-5132Aug 30, 2012risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."
Page 6 of 10