VYPR

Vendor CVEs

MyBB

All CVEs

240 total · sorted by risk
  • CVE-2017-8104MedApr 24, 2017
    risk 0.35cvss 5.3epss 0.03

    In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.

  • CVE-2016-9411MedJan 31, 2017
    risk 0.35cvss 5.3epss 0.02

    The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.

  • CVE-2021-47934MedMay 16, 2026
    risk 0.34cvss 5.3epss 0.00

    MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in…

  • CVE-2022-43709MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.

  • CVE-2018-7305MedFeb 21, 2018
    risk 0.32cvss 4.9epss 0.00

    MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts.

  • CVE-2026-45121MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected calendar-selection paths in…

  • CVE-2026-45120MedAug 18, 2026
    risk 0.28cvss 5.4epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The private-event check used by get_events() in…

  • CVE-2018-1000503MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view posts from private forums without having the password. This attack appear to be exploitable via Subscribe to a forum through IDOR. This vulnerability appears to…

  • CVE-2026-46482MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value. [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:…

  • CVE-2026-45734MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass CAPTCHA controls through challenge replay. The successful validation paths in contact.php,…

  • CVE-2026-45125MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the stored username for…

  • CVE-2026-45129MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Admin CP Home, Preferences,…

  • CVE-2026-45119MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially crafted URL. The do=all control flow in…

  • CVE-2026-47245MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate reciprocal buddy-list updates correctly. The usercp.php?action=do_editlists delete handler removes the selected entry from the acting user's list and then…

  • CVE-2026-45124MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is…

  • CVE-2026-45123MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in…

  • CVE-2026-45122MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user…

  • CVE-2026-45128LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a specially crafted URL. The Set as Default…

  • CVE-2026-45127LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially crafted URL. The Resend route in Admin CP,…

  • CVE-2026-45126LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with a specially crafted URL. The controller…

  • CVE-2008-0382Jan 22, 2008
    risk 0.06cvss —epss 0.42

    Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

  • CVE-2019-9650MedMar 11, 2019
    risk 0.03cvss 6.1epss 0.04

    An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.

  • CVE-2019-3501MedJan 2, 2019
    risk 0.03cvss 4.8epss 0.03

    The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile.

  • CVE-2014-9241Dec 3, 2014
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to usercp.php, or (3) title…

  • CVE-2014-9240Dec 3, 2014
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.

  • CVE-2011-5278Apr 8, 2014
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allows remote attackers to execute arbitrary SQL commands via the afs_bar_right parameter.

  • CVE-2011-5277Apr 8, 2014
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4) afs_bar_left, (5)…

  • CVE-2013-6936Dec 4, 2013
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.

  • CVE-2012-5909Nov 17, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.

  • CVE-2012-5908Nov 17, 2012
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.

  • CVE-2010-5096Aug 13, 2012
    risk 0.03cvss —epss 0.06

    Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this…

  • CVE-2011-4569Nov 29, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.

  • CVE-2009-4813Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.

  • CVE-2009-2230Jun 26, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.

  • CVE-2008-6198Feb 20, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2008-0787Feb 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.

  • CVE-2008-0383Jan 22, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a…

  • CVE-2007-2212Apr 24, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2007-2211Apr 24, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.

  • CVE-2007-1963Apr 11, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.

  • CVE-2007-1906Apr 10, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.

  • CVE-2006-3775Jul 24, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

  • CVE-2006-2336May 12, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.

  • CVE-2006-2070Apr 27, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action.

  • CVE-2006-1974Apr 21, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.

  • CVE-2006-1912Apr 20, 2006
    risk 0.03cvss —epss 0.02

    MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site…

  • CVE-2006-0470Jan 31, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.

  • CVE-2006-0442Jan 26, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. NOTE: These are…

  • CVE-2005-3326Oct 27, 2005
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.

  • CVE-2005-2580Aug 16, 2005
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5)…