VYPR

Mybb

by MyBB

Source repositories

CVEs (201)

  • CVE-2023-41362HigAug 29, 2023
    risk 0.00cvss 7.2epss 0.02

    MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

  • CVE-2022-39265HigOct 6, 2022
    risk 0.00cvss 7.2epss 0.02

    MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remote Code…

  • CVE-2021-27279MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).

  • CVE-2020-15139HigAug 10, 2020
    risk 0.00cvss 8.8epss 0.01

    In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as…

  • CVE-2015-4552Sep 3, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.

  • CVE-2015-2786Mar 29, 2015
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."

  • CVE-2015-2352Mar 19, 2015
    risk 0.00cvss —epss 0.01

    The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.

  • CVE-2015-2335Mar 18, 2015
    risk 0.00cvss —epss 0.01

    A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

  • CVE-2015-2334Mar 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2015-2333Mar 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-2332Mar 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-2149Mar 18, 2015
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types module…

  • CVE-2014-5248Aug 14, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.

  • CVE-2014-1840Mar 3, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.

  • CVE-2013-7288Jan 10, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the mycode_parse_video function in inc/class_parser.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via vectors related to Yahoo video URLs.

  • CVE-2013-7275Jan 8, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup.

  • CVE-2011-5133Aug 30, 2012
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."

  • CVE-2011-5132Aug 30, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."

  • CVE-2011-5131Aug 30, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the language parameter.

  • CVE-2012-2327Aug 13, 2012
    risk 0.00cvss —epss 0.01

    MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.

Page 7 of 11