Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb mybb 1.00 vulnerabilities and exploits
(subscribe to this query)
890
VMScore
CVE-2006-0218
Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) prior to 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and pro...
Mybb Mybb 1.0
Mybb Mybb
Mybb Mybb 1.00
383
VMScore
CVE-2008-3334
Cross-site scripting (XSS) vulnerability in MyBB 1.2.x prior to 1.2.14 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.
Mybb Mybb 1.04
Mybb Mybb 1.1.0
Mybb Mybb 1.1.7
Mybb Mybb 1.1.8
Mybb Mybb 1.2.3
Mybb Mybb 1.2.4
Mybb Mybb 1.2.5
Mybb Mybb 1.00
Mybb Mybb 1.01
Mybb Mybb 1.1.3
Mybb Mybb 1.1.4
Mybb Mybb 1.2.10
Mybb Mybb 1.2.11
Mybb Mybb 1.2.8
Mybb Mybb 1.2.9
Mybb Mybb 1.02
Mybb Mybb 1.03
Mybb Mybb 1.1.5
Mybb Mybb 1.1.6
Mybb Mybb 1.2.12
Mybb Mybb 1.2.2
Mybb Mybb
668
VMScore
CVE-2008-3965
SQL injection vulnerability in misc.php in MyBB (aka MyBulletinBoard) prior to 1.4.1 allows remote malicious users to execute arbitrary SQL commands via a certain editor field.
Mybb Mybb 1.2.12
Mybb Mybb 1.2.10
Mybb Mybb 1.2.7
Mybb Mybb 1.2.13
Mybb Mybb 1.1.7
Mybb Mybb 1.1.3
Mybb Mybb 1.02
Mybb Mybb 1.2.3
Mybb Mybb 1.2.4
Mybb Mybb
Mybb Mybb 1.2.11
Mybb Mybb 1.2.8
Mybb Mybb 1.2.6
Mybb Mybb 1.1.2
Mybb Mybb 1.1.0
Mybb Mybb 1.2.1
Mybb Mybb 1.2.2
Mybb Mybb 1.2
Mybb Mybb 1.2.9
Mybb Mybb 1.1.4
Mybb Mybb 1.1.5
Mybb Mybb 1.03
383
VMScore
CVE-2008-3966
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) prior to 1.4.1 allow remote malicious users to inject arbitrary web script or HTML via (1) a certain referrer field in usercp2.php, (2) a certain location field in inc/functions_online.php, and cert...
Mybb Mybb 1.2.0
Mybb Mybb 1.00
Mybb Mybb 1.2
Mybb Mybb 1.1.6
Mybb Mybb 1.1.8
Mybb Mybb 1.01
Mybb Mybb 1.04
Mybb Mybb 1.2.12
Mybb Mybb 1.2.10
Mybb Mybb 1.2.13
Mybb Mybb 1.1.7
Mybb Mybb 1.1.3
Mybb Mybb 1.02
Mybb Mybb 1.2.3
Mybb Mybb 1.2.4
Mybb Mybb 1.2.5
Mybb Mybb
Mybb Mybb 1.2.11
Mybb Mybb 1.2.6
Mybb Mybb 1.2.7
Mybb Mybb 1.1.2
Mybb Mybb 1.1.0
668
VMScore
CVE-2008-3967
moderation.php in MyBB (aka MyBulletinBoard) prior to 1.4.1 does not properly check for moderator privileges, which has unknown impact and remote attack vectors.
Mybb Mybb
Mybb Mybb 1.2.9
Mybb Mybb 1.2.8
Mybb Mybb 1.1.4
Mybb Mybb 1.1.5
Mybb Mybb 1.00
Mybb Mybb 1.2
Mybb Mybb 1.1.6
Mybb Mybb 1.1.8
Mybb Mybb 1.04
Mybb Mybb 1.03
Mybb Mybb 1.2.10
Mybb Mybb 1.2.0
Mybb Mybb 1.2.13
Mybb Mybb 1.1.7
Mybb Mybb 1.1.3
Mybb Mybb 1.02
Mybb Mybb 1.01
Mybb Mybb 1.2.4
Mybb Mybb 1.2.5
Mybb Mybb 1.1.1
Mybb Mybb 1.2.1
605
VMScore
CVE-2010-4627
Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) prior to 1.4.12 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Mybb Mybb 1.4.3
Mybb Mybb 1.4.2
Mybb Mybb 1.2.9
Mybb Mybb 1.2.8
Mybb Mybb 1.2.4
Mybb Mybb 1.2.5
Mybb Mybb 1.1.7
Mybb Mybb 1.1.3
Mybb Mybb 1.1.1
Mybb Mybb
Mybb Mybb 1.4.0
Mybb Mybb 1.2.11
Mybb Mybb 1.2.6
Mybb Mybb 1.2.7
Mybb Mybb 1.1.6
Mybb Mybb 1.1.8
Mybb Mybb 1.00
Mybb Mybb 1.02
Mybb Mybb 1.4.10
Mybb Mybb 1.4.9
Mybb Mybb 1.2.12
Mybb Mybb 1.2.10
312
VMScore
CVE-2010-4624
MyBB (aka MyBulletinBoard) prior to 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created.
Mybb Mybb 1.4.6
Mybb Mybb 1.4.3
Mybb Mybb 1.2
Mybb Mybb 1.2.9
Mybb Mybb 1.2.4
Mybb Mybb 1.2.5
Mybb Mybb 1.1.0
Mybb Mybb 1.1.3
Mybb Mybb 1.4.9
Mybb Mybb 1.4.8
Mybb Mybb 1.2.10
Mybb Mybb 1.2.0
Mybb Mybb 1.2.2
Mybb Mybb 1.2.3
Mybb Mybb 1.1.5
Mybb Mybb 1.1.2
Mybb Mybb 1.04
Mybb Mybb 1.03
Mybb Mybb 1.4.2
Mybb Mybb 1.4.0
Mybb Mybb 1.2.8
Mybb Mybb 1.2.6
445
VMScore
CVE-2010-4625
MyBB (aka MyBulletinBoard) prior to 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote malicious users to obtain sensitive information by reading the Latest Threads block of the Portal Page.
Mybb Mybb
Mybb Mybb 1.2.11
Mybb Mybb 1.2.12
Mybb Mybb 1.2.7
Mybb Mybb 1.2.13
Mybb Mybb 1.1.6
Mybb Mybb 1.1.8
Mybb Mybb 1.02
Mybb Mybb 1.01
Mybb Mybb 1.4.2
Mybb Mybb 1.4.0
Mybb Mybb 1.2.8
Mybb Mybb 1.2.6
Mybb Mybb 1.2.5
Mybb Mybb 1.1.7
Mybb Mybb 1.1.1
Mybb Mybb 1.00
Mybb Mybb 1.4.10
Mybb Mybb 1.4.9
Mybb Mybb 1.2.10
Mybb Mybb 1.2.0
Mybb Mybb 1.2.1
454
VMScore
CVE-2010-4626
The my_rand function in functions.php in MyBB (aka MyBulletinBoard) prior to 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote malicious users to obtain access to an arbitrary account by requesting a reset of the account's password, and ...
Mybb Mybb 1.4.10
Mybb Mybb 1.4.9
Mybb Mybb 1.2.12
Mybb Mybb 1.2.10
Mybb Mybb 1.2.1
Mybb Mybb 1.2.2
Mybb Mybb 1.1.4
Mybb Mybb 1.1.5
Mybb Mybb 1.01
Mybb Mybb 1.04
Mybb Mybb 1.03
Mybb Mybb 1.4.8
Mybb Mybb 1.4.6
Mybb Mybb 1.2.0
Mybb Mybb 1.2
Mybb Mybb 1.2.9
Mybb Mybb 1.2.3
Mybb Mybb 1.2.4
Mybb Mybb 1.1.2
Mybb Mybb 1.1.0
Mybb Mybb 1.4.3
Mybb Mybb 1.4.2
445
VMScore
CVE-2010-4628
member.php in MyBB (aka MyBulletinBoard) prior to 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote malicious users to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users tab...
Mybb Mybb
Mybb Mybb 1.4.10
Mybb Mybb 1.2.12
Mybb Mybb 1.2.10
Mybb Mybb 1.2.13
Mybb Mybb 1.2.1
Mybb Mybb 1.1.8
Mybb Mybb 1.1.4
Mybb Mybb 1.01
Mybb Mybb 1.04
Mybb Mybb 1.4.9
Mybb Mybb 1.4.8
Mybb Mybb 1.2.0
Mybb Mybb 1.2
Mybb Mybb 1.2.2
Mybb Mybb 1.2.3
Mybb Mybb 1.1.5
Mybb Mybb 1.1.2
Mybb Mybb 1.03
Mybb Mybb 1.4.6
Mybb Mybb 1.4.3
Mybb Mybb 1.2.9
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
administrator privileges
CVE-2024-1579
hardcoded
CVE-2023-20198
CVE-2024-33587
CVE-2024-33449
CVE-2024-4308
HTML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »