Vendor CVEs
MyBB
All CVEs
222 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25116 | Med | 0.40 | 6.1 | 0.00 | Jan 23, 2026 | MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution. | ||
| CVE-2023-28467 | Med | 0.40 | 6.1 | 0.01 | May 22, 2023 | In MyBB before 1.8.34, there is XSS in the User CP module via the user email field. | ||
| CVE-2022-28354 | Med | 0.40 | 6.1 | 0.01 | Apr 24, 2023 | In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period. | ||
| CVE-2022-28353 | Med | 0.40 | 6.1 | 0.01 | Apr 16, 2023 | In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS. | ||
| CVE-2022-43708 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2022 | MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name | ||
| CVE-2022-43707 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2022 | MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data | ||
| CVE-2021-27949 | Med | 0.40 | 6.1 | 0.01 | Mar 15, 2021 | Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools. | ||
| CVE-2019-20225 | Med | 0.40 | 6.1 | 0.01 | Jan 2, 2020 | MyBB before 1.8.22 allows an open redirect on login. | ||
| CVE-2019-3578 | Med | 0.40 | 6.1 | 0.01 | Jun 6, 2019 | MyBB 1.8.19 has XSS in the resetpassword function. | ||
| CVE-2018-19202 | Med | 0.40 | 6.1 | 0.01 | Apr 11, 2019 | A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter. | ||
| CVE-2018-19201 | Med | 0.40 | 6.1 | 0.01 | Mar 29, 2019 | A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter. | ||
| CVE-2018-10678 | Med | 0.40 | 6.1 | 0.01 | May 13, 2018 | MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks. | ||
| CVE-2017-8103 | Med | 0.40 | 6.1 | 0.01 | Apr 24, 2017 | In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event. | ||
| CVE-2016-9421 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9419 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9409 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs. | ||
| CVE-2016-9408 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users. | ||
| CVE-2016-9407 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs. | ||
| CVE-2016-9406 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9405 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-9404 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login. | ||
| CVE-2015-8976 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files." | ||
| CVE-2015-8975 | Med | 0.40 | 6.1 | 0.02 | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2018-11715 | Med | 0.38 | 5.4 | 0.02 | Jun 4, 2018 | The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject. | ||
| CVE-2018-10580 | Med | 0.38 | 5.4 | 0.02 | May 11, 2018 | The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field. | ||
| CVE-2018-10365 | Med | 0.38 | 5.4 | 0.02 | May 1, 2018 | An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized. | ||
| CVE-2017-16781 | Med | 0.38 | 5.4 | 0.02 | Nov 10, 2017 | The installer in MyBB before 1.8.13 has XSS. | ||
| CVE-2021-39338 | Med | 0.36 | 5.5 | 0.01 | Oct 15, 2021 | The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative user access to inject… | ||
| CVE-2019-6979 | Med | 0.36 | 6.1 | 0.02 | Jan 28, 2019 | An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field. | ||
| CVE-2018-14888 | Med | 0.36 | 6.1 | 0.04 | Aug 14, 2018 | inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject. | ||
| CVE-2018-25249 | Med | 0.35 | 6.4 | 0.00 | Apr 4, 2026 | MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other… | ||
| CVE-2023-53978 | Med | 0.35 | 5.4 | 0.00 | Dec 22, 2025 | myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the… | ||
| CVE-2023-53977 | Med | 0.35 | 5.4 | 0.00 | Dec 22, 2025 | myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the… | ||
| CVE-2023-53976 | Med | 0.35 | 5.4 | 0.00 | Dec 22, 2025 | myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in… | ||
| CVE-2024-52702 | Med | 0.35 | 5.4 | 0.00 | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website… | ||
| CVE-2023-45556 | Med | 0.35 | 5.4 | 0.01 | Nov 6, 2023 | Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component. | ||
| CVE-2023-27890 | Med | 0.35 | 5.4 | 0.01 | Apr 14, 2023 | The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2021-41866 | Med | 0.35 | 5.4 | 0.00 | Oct 26, 2021 | MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly. | ||
| CVE-2020-19049 | Med | 0.35 | 5.4 | 0.01 | Aug 31, 2021 | Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'. | ||
| CVE-2020-19048 | Med | 0.35 | 5.4 | 0.01 | Aug 31, 2021 | Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'. | ||
| CVE-2014-3827 | Med | 0.35 | 5.4 | 0.01 | Feb 11, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser… | ||
| CVE-2014-3826 | Med | 0.35 | 5.4 | 0.01 | Feb 11, 2020 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module. | ||
| CVE-2019-3579 | Med | 0.35 | 5.3 | 0.02 | Jun 6, 2019 | MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter. | ||
| CVE-2018-14724 | Med | 0.35 | 5.4 | 0.01 | Mar 21, 2019 | In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page. | ||
| CVE-2018-11430 | Med | 0.35 | 5.4 | 0.01 | May 28, 2018 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea. | ||
| CVE-2018-6844 | Med | 0.35 | 5.4 | 0.01 | Feb 8, 2018 | MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen. | ||
| CVE-2017-8104 | Med | 0.35 | 5.3 | 0.03 | Apr 24, 2017 | In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter. | ||
| CVE-2016-9411 | Med | 0.35 | 5.3 | 0.02 | Jan 31, 2017 | The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails. | ||
| CVE-2021-47934 | Med | 0.34 | 5.3 | 0.00 | May 16, 2026 | MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in… | ||
| CVE-2022-43709 | Med | 0.32 | 4.9 | 0.01 | Nov 22, 2022 | MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings. |
- risk 0.40cvss 6.1epss 0.00
MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.
- risk 0.40cvss 6.1epss 0.01
In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
- risk 0.40cvss 6.1epss 0.01
In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.
- risk 0.40cvss 6.1epss 0.01
In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.
- risk 0.40cvss 6.1epss 0.00
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
- risk 0.40cvss 6.1epss 0.00
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data
- risk 0.40cvss 6.1epss 0.01
Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
- risk 0.40cvss 6.1epss 0.01
MyBB before 1.8.22 allows an open redirect on login.
- risk 0.40cvss 6.1epss 0.01
MyBB 1.8.19 has XSS in the resetpassword function.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.
- risk 0.40cvss 6.1epss 0.01
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
- risk 0.40cvss 6.1epss 0.01
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.38cvss 5.4epss 0.02
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
- risk 0.38cvss 5.4epss 0.02
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.
- risk 0.38cvss 5.4epss 0.02
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.
- risk 0.38cvss 5.4epss 0.02
The installer in MyBB before 1.8.13 has XSS.
- risk 0.36cvss 5.5epss 0.01
The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative user access to inject…
- risk 0.36cvss 6.1epss 0.02
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field.
- risk 0.36cvss 6.1epss 0.04
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.
- risk 0.35cvss 6.4epss 0.00
MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other…
- risk 0.35cvss 5.4epss 0.00
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the…
- risk 0.35cvss 5.4epss 0.00
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the…
- risk 0.35cvss 5.4epss 0.00
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in…
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website…
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.
- risk 0.35cvss 5.4epss 0.01
The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.35cvss 5.4epss 0.00
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
- risk 0.35cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser…
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.
- risk 0.35cvss 5.3epss 0.02
MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter.
- risk 0.35cvss 5.4epss 0.01
In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
- risk 0.35cvss 5.4epss 0.01
MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.
- risk 0.35cvss 5.3epss 0.03
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
- risk 0.35cvss 5.3epss 0.02
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.
- risk 0.34cvss 5.3epss 0.00
MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in…
- risk 0.32cvss 4.9epss 0.01
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.
Page 2 of 5