Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb mybb vulnerabilities and exploits
(subscribe to this query)
10
CVSSv3
CVE-2015-8974
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allows remote malicious users to execute arbitrary SQL commands via unspecified vector...
Mybb Mybb 1.8.4
Mybb Mybb 1.8.2
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb
Mybb Mybb 1.8.5
Mybb Mybb 1.8.3
Mybb Merge System
9.8
CVSSv3
CVE-2020-22612
Installer RCE on settings file write in MyBB prior to 1.8.22.
Mybb Mybb
9.8
CVSSv3
CVE-2017-16780
The installer in MyBB prior to 1.8.13 allows remote malicious users to execute arbitrary code by writing to the configuration file.
Mybb Mybb
1 EDB exploit
9.8
CVSSv3
CVE-2017-14652
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin prior to 4.5.8 for MyBB allows an unauthenticated remote malicious user to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration process.
Tapatalk Tapatalk
9.8
CVSSv3
CVE-2016-9403
newreply.php in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allows remote malicious users to have unspecified impact by leveraging a missing permission check.
Mybb Merge System
Mybb Mybb
9.8
CVSSv3
CVE-2016-9416
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Mybb Merge System
Mybb Mybb
9.8
CVSSv3
CVE-2016-9402
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Mybb Mybb
Mybb Merge System
9.8
CVSSv3
CVE-2016-9412
MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allow malicious users to have unspecified impact via vectors related to low adminsid and sid entropy.
Mybb Mybb
Mybb Merge System
9.8
CVSSv3
CVE-2016-9420
MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allow remote malicious users to have unspecified impact via vectors related to "loose comparison false positives."
Mybb Mybb
Mybb Merge System
8.8
CVSSv3
CVE-2021-27890
SQL Injection vulnerablity in MyBB prior to 1.8.26 via theme properties included in theme XML files.
Mybb Mybb
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »