VYPR

Vendor CVEs

MyBB

All CVEs

240 total · sorted by risk
  • CVE-2025-48941MedJun 2, 2025
    risk 0.00cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads containing specified text in the title.…

  • CVE-2025-48940HigJun 2, 2025
    risk 0.00cvss 7.2epss 0.01

    MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the…

  • CVE-2024-23336MedMay 1, 2024
    risk 0.00cvss 5.0epss 0.00

    MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result in a Server-Side Request Forgery (SSRF) vulnerability. The Configuration File's _Disallowed Remote Addresses_ list…

  • CVE-2024-23335MedMay 1, 2024
    risk 0.00cvss 4.7epss 0.01

    MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolves this issue. Users are…

  • CVE-2023-46251HigNov 6, 2023
    risk 0.00cvss 7.5epss 0.00

    MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual…

  • CVE-2023-41362HigAug 29, 2023
    risk 0.00cvss 7.2epss 0.02

    MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

  • CVE-2022-39265HigOct 6, 2022
    risk 0.00cvss 7.2epss 0.02

    MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remote Code…

  • CVE-2021-28115MedMar 9, 2021
    risk 0.00cvss 6.1epss 0.01

    The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.

  • CVE-2021-27279MedFeb 22, 2021
    risk 0.00cvss 5.4epss 0.01

    MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).

  • CVE-2021-3350MedFeb 1, 2021
    risk 0.00cvss 6.1epss 0.01

    deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.

  • CVE-2020-15139HigAug 10, 2020
    risk 0.00cvss 8.8epss 0.01

    In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as…

  • CVE-2018-11092MedMay 21, 2018
    risk 0.00cvss 6.5epss 0.01

    An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.

  • CVE-2015-4552Sep 3, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.

  • CVE-2015-2786Mar 29, 2015
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."

  • CVE-2015-2352Mar 19, 2015
    risk 0.00cvss —epss 0.01

    The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.

  • CVE-2015-2335Mar 18, 2015
    risk 0.00cvss —epss 0.01

    A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

  • CVE-2015-2334Mar 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2015-2333Mar 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-2332Mar 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-2149Mar 18, 2015
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types module…

  • CVE-2014-5248Aug 14, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.

  • CVE-2014-1840Mar 3, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.

  • CVE-2013-7288Jan 10, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the mycode_parse_video function in inc/class_parser.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via vectors related to Yahoo video URLs.

  • CVE-2013-7275Jan 8, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup.

  • CVE-2011-5133Aug 30, 2012
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."

  • CVE-2011-5132Aug 30, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."

  • CVE-2011-5131Aug 30, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the language parameter.

  • CVE-2012-2327Aug 13, 2012
    risk 0.00cvss —epss 0.01

    MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.

  • CVE-2012-2326Aug 13, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote administrators to inject arbitrary web script or HTML via a malformed file name in an orphaned attachment.

  • CVE-2012-2325Aug 13, 2012
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the User Inline Moderation feature in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote administrators to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2012-2324Aug 13, 2012
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) Mail Log in the Admin Control Panel (ACP).

  • CVE-2011-3759Sep 23, 2011
    risk 0.00cvss —epss 0.01

    MyBB (aka MyBulletinBoard) 1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/3rdparty/diff/Diff/ThreeWay.php and certain other files.

  • CVE-2010-4629Dec 30, 2010
    risk 0.00cvss —epss 0.02

    MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to…

  • CVE-2010-4628Dec 30, 2010
    risk 0.00cvss —epss 0.02

    member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table.

  • CVE-2010-4627Dec 30, 2010
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2010-4626Dec 30, 2010
    risk 0.00cvss —epss 0.02

    The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then…

  • CVE-2010-4625Dec 30, 2010
    risk 0.00cvss —epss 0.02

    MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Threads block of the Portal Page.

  • CVE-2010-4624Dec 30, 2010
    risk 0.00cvss —epss 0.02

    MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created.

  • CVE-2010-4522Dec 30, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) editpost.php, (2) member.php, and (3) newreply.php.

  • CVE-2009-4448Dec 29, 2009
    risk 0.00cvss —epss 0.02

    inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and…

  • CVE-2008-7082Aug 25, 2009
    risk 0.00cvss —epss 0.01

    MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection…

  • CVE-2008-4930Nov 4, 2008
    risk 0.00cvss —epss 0.01

    MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded file with a nonstandard file type that contains HTML sequences, which allows remote attackers to cause that file to be processed as HTML by Internet Explorer's content inspection, aka "Incomplete protection…

  • CVE-2008-4928Nov 4, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the redirect function in functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter in a removesubscriptions action to moderation.php, related to use of the…

  • CVE-2008-3967Sep 11, 2008
    risk 0.00cvss —epss 0.01

    moderation.php in MyBB (aka MyBulletinBoard) before 1.4.1 does not properly check for moderator privileges, which has unknown impact and remote attack vectors.

  • CVE-2008-3966Sep 11, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via (1) a certain referrer field in usercp2.php, (2) a certain location field in inc/functions_online.php, and certain (3)…

  • CVE-2008-3965Sep 11, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.4.1 allows remote attackers to execute arbitrary SQL commands via a certain editor field.

  • CVE-2008-3334Jul 27, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.

  • CVE-2008-3071Jul 8, 2008
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in inc/class_language.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $language variable.

  • CVE-2008-3069Jul 8, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB before 1.2.13 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) portal.php and (2) inc/functions_post.php.

  • CVE-2008-3070Jul 8, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in inc/datahandler/user.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $user['language'] variable, probably related to SQL injection.

Page 4 of 5