VYPR

Vendor CVEs

MyBB

All CVEs

222 total · sorted by risk
  • CVE-2011-10018CriAug 13, 2025
    risk 0.67cvss 9.8epss 0.02

    myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging…

  • CVE-2017-16780CriNov 10, 2017
    risk 0.67cvss 9.8epss 0.06

    The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.

  • CVE-2015-8974CriJan 31, 2017
    risk 0.65cvss 10.0epss 0.02

    SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2020-22612CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Installer RCE on settings file write in MyBB before 1.8.22.

  • CVE-2017-14652CriSep 21, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration process.

  • CVE-2016-9420CriJan 31, 2017
    risk 0.64cvss 9.8epss 0.03

    MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "loose comparison false positives."

  • CVE-2016-9416CriJan 31, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-9412CriJan 31, 2017
    risk 0.64cvss 9.8epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy.

  • CVE-2016-9403CriJan 31, 2017
    risk 0.64cvss 9.8epss 0.03

    newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.

  • CVE-2016-9402CriJan 31, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2021-27946HigMar 15, 2021
    risk 0.61cvss 8.8epss 0.04

    SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).

  • CVE-2021-27890HigMar 15, 2021
    risk 0.61cvss 8.8epss 0.11

    SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.

  • CVE-2018-14575HigMar 21, 2019
    risk 0.60cvss 8.8epss 0.02

    Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

  • CVE-2023-53979HigDec 22, 2025
    risk 0.57cvss 8.8epss 0.01

    MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language…

  • CVE-2019-12363HigJul 11, 2019
    risk 0.57cvss 8.8epss 0.01

    An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?action=mybb2fa&do=deactivate (or usercp.php?action=mybb2fa&do=activate). A deactivate…

  • CVE-2019-12830HigJun 15, 2019
    risk 0.57cvss 8.7epss 0.01

    In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.

  • CVE-2015-8973HigJan 31, 2017
    risk 0.54cvss 8.3epss 0.02

    xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.

  • CVE-2021-3337HigJan 28, 2021
    risk 0.53cvss 7.5epss 0.11

    The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

  • CVE-2017-7566HigApr 6, 2017
    risk 0.50cvss 7.7epss 0.02

    MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.

  • CVE-2025-29460HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2025-29459HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2025-29458HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2025-29457HigApr 17, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

  • CVE-2022-24734HigMar 9, 2022
    risk 0.49cvss 7.2epss 0.78

    MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change…

  • CVE-2016-9418HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.

  • CVE-2016-9415HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."

  • CVE-2016-9414HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missing directory listing protection in upload directories.

  • CVE-2016-9410HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via vectors involving templates.

  • CVE-2015-8977HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.

  • CVE-2008-4929HigNov 4, 2008
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.

  • CVE-2016-9417HigJan 31, 2017
    risk 0.48cvss 7.4epss 0.02

    The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

  • CVE-2018-25309HigApr 29, 2026
    risk 0.47cvss 7.2epss 0.00

    MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary…

  • CVE-2022-45867HigJan 3, 2023
    risk 0.47cvss 7.2epss 0.01

    MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.

  • CVE-2021-43281HigNov 4, 2021
    risk 0.47cvss 7.2epss 0.01

    MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type "php" with…

  • CVE-2021-27948HigMar 15, 2021
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).

  • CVE-2021-27947HigMar 15, 2021
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).

  • CVE-2019-12831HigJun 15, 2019
    risk 0.47cvss 7.2epss 0.01

    In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by…

  • CVE-2018-14392MedJul 19, 2018
    risk 0.47cvss 6.1epss 0.49

    The New Threads plugin before 1.2 for MyBB has XSS.

  • CVE-2018-1000502HigJun 26, 2018
    risk 0.47cvss 7.2epss 0.01

    MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance -> Task Manager -> Add New Task) that can result in Allows Local File Inclusion on modern PHP versions and Remote File Inclusion on ancient PHP versions. This attack appear to be…

  • CVE-2018-11502MedAug 24, 2018
    risk 0.45cvss 6.5epss 0.02

    An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.

  • CVE-2018-17128MedSep 17, 2018
    risk 0.44cvss 5.4epss 0.75

    A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.

  • CVE-2021-27889MedMar 15, 2021
    risk 0.43cvss 6.1epss 0.05

    Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.

  • CVE-2018-15596MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.02

    An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't…

  • CVE-2016-9413MedJan 31, 2017
    risk 0.42cvss 6.5epss 0.02

    The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

  • CVE-2009-4449MedDec 29, 2009
    risk 0.42cvss 6.5epss 0.03

    Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and…

  • CVE-2018-25250HigApr 4, 2026
    risk 0.40cvss 7.2epss 0.00

    MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that…

  • CVE-2018-25248HigApr 4, 2026
    risk 0.40cvss 7.2epss 0.00

    MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes…

  • CVE-2018-25247MedApr 4, 2026
    risk 0.40cvss 6.1epss 0.00

    MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the unsanitized subject is rendered, executing…

  • CVE-2021-47905MedJan 23, 2026
    risk 0.40cvss 6.1epss 0.00

    MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicious scripts that will execute in the admin interface when viewing delete account reasons.

  • CVE-2018-25132MedJan 23, 2026
    risk 0.40cvss 6.1epss 0.00

    MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

Page 1 of 5