VYPR

Vendor CVEs

MyBB

All CVEs

222 total · sorted by risk
  • CVE-2018-25116MedJan 23, 2026
    risk 0.40cvss 6.1epss 0.00

    MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.

  • CVE-2023-28467MedMay 22, 2023
    risk 0.40cvss 6.1epss 0.01

    In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

  • CVE-2022-28354MedApr 24, 2023
    risk 0.40cvss 6.1epss 0.01

    In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.

  • CVE-2022-28353MedApr 16, 2023
    risk 0.40cvss 6.1epss 0.01

    In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.

  • CVE-2022-43708MedNov 22, 2022
    risk 0.40cvss 6.1epss 0.00

    MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name

  • CVE-2022-43707MedNov 22, 2022
    risk 0.40cvss 6.1epss 0.00

    MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data

  • CVE-2021-27949MedMar 15, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.

  • CVE-2019-20225MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.01

    MyBB before 1.8.22 allows an open redirect on login.

  • CVE-2019-3578MedJun 6, 2019
    risk 0.40cvss 6.1epss 0.01

    MyBB 1.8.19 has XSS in the resetpassword function.

  • CVE-2018-19202MedApr 11, 2019
    risk 0.40cvss 6.1epss 0.01

    A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.

  • CVE-2018-19201MedMar 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.

  • CVE-2018-10678MedMay 13, 2018
    risk 0.40cvss 6.1epss 0.01

    MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.

  • CVE-2017-8103MedApr 24, 2017
    risk 0.40cvss 6.1epss 0.01

    In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.

  • CVE-2016-9421MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-9419MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-9409MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.

  • CVE-2016-9408MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.

  • CVE-2016-9407MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs.

  • CVE-2016-9406MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-9405MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-9404MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.

  • CVE-2015-8976MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."

  • CVE-2015-8975MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2018-11715MedJun 4, 2018
    risk 0.38cvss 5.4epss 0.02

    The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.

  • CVE-2018-10580MedMay 11, 2018
    risk 0.38cvss 5.4epss 0.02

    The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

  • CVE-2018-10365MedMay 1, 2018
    risk 0.38cvss 5.4epss 0.02

    An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.

  • CVE-2017-16781MedNov 10, 2017
    risk 0.38cvss 5.4epss 0.02

    The installer in MyBB before 1.8.13 has XSS.

  • CVE-2021-39338MedOct 15, 2021
    risk 0.36cvss 5.5epss 0.01

    The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative user access to inject…

  • CVE-2019-6979MedJan 28, 2019
    risk 0.36cvss 6.1epss 0.02

    An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field.

  • CVE-2018-14888MedAug 14, 2018
    risk 0.36cvss 6.1epss 0.04

    inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.

  • CVE-2018-25249MedApr 4, 2026
    risk 0.35cvss 6.4epss 0.00

    MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other…

  • CVE-2023-53978MedDec 22, 2025
    risk 0.35cvss 5.4epss 0.00

    myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the…

  • CVE-2023-53977MedDec 22, 2025
    risk 0.35cvss 5.4epss 0.00

    myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the…

  • CVE-2023-53976MedDec 22, 2025
    risk 0.35cvss 5.4epss 0.00

    myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in…

  • CVE-2024-52702MedNov 20, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website…

  • CVE-2023-45556MedNov 6, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.

  • CVE-2023-27890MedApr 14, 2023
    risk 0.35cvss 5.4epss 0.01

    The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2021-41866MedOct 26, 2021
    risk 0.35cvss 5.4epss 0.00

    MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.

  • CVE-2020-19049MedAug 31, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.

  • CVE-2020-19048MedAug 31, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.

  • CVE-2014-3827MedFeb 11, 2020
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser…

  • CVE-2014-3826MedFeb 11, 2020
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.

  • CVE-2019-3579MedJun 6, 2019
    risk 0.35cvss 5.3epss 0.02

    MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter.

  • CVE-2018-14724MedMar 21, 2019
    risk 0.35cvss 5.4epss 0.01

    In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.

  • CVE-2018-11430MedMay 28, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.

  • CVE-2018-6844MedFeb 8, 2018
    risk 0.35cvss 5.4epss 0.01

    MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.

  • CVE-2017-8104MedApr 24, 2017
    risk 0.35cvss 5.3epss 0.03

    In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.

  • CVE-2016-9411MedJan 31, 2017
    risk 0.35cvss 5.3epss 0.02

    The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.

  • CVE-2021-47934MedMay 16, 2026
    risk 0.34cvss 5.3epss 0.00

    MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in…

  • CVE-2022-43709MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.

Page 2 of 5