Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb merge system vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2016-9411
The Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allows remote malicious users to obtain the installation path via vectors involving sending mails.
Mybb Merge System
Mybb Mybb
668
VMScore
CVE-2016-9412
MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allow malicious users to have unspecified impact via vectors related to low adminsid and sid entropy.
Mybb Mybb
Mybb Merge System
383
VMScore
CVE-2016-9413
The Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allows remote malicious users to conduct clickjacking attacks via unspecified vectors.
Mybb Mybb
Mybb Merge System
445
VMScore
CVE-2016-9414
MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allow remote malicious users to obtain sensitive information by leveraging missing directory listing protection in upload directories.
Mybb Merge System
Mybb Mybb
668
VMScore
CVE-2016-9416
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Mybb Merge System
Mybb Mybb
516
VMScore
CVE-2016-9417
The fetch_remote_file function in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
Mybb Mybb
Mybb Merge System
668
VMScore
CVE-2016-9420
MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allow remote malicious users to have unspecified impact via vectors related to "loose comparison false positives."
Mybb Mybb
Mybb Merge System
668
VMScore
CVE-2015-8974
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allows remote malicious users to execute arbitrary SQL commands via unspecified vector...
Mybb Mybb 1.8.4
Mybb Mybb 1.8.2
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb
Mybb Mybb 1.8.5
Mybb Mybb 1.8.3
Mybb Merge System
445
VMScore
CVE-2015-8977
MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allow remote malicious users to obtain the installation path via vectors involving error log files.
Mybb Mybb 1.8.5
Mybb Mybb 1.8.3
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb
Mybb Merge System
Mybb Mybb 1.8.4
Mybb Mybb 1.8.2
668
VMScore
CVE-2015-8973
xmlhttp.php in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allows remote malicious users to bypass intended access restrictions via vectors related to the forum password.
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Mybb 1.8.0
Mybb Mybb
Mybb Merge System
Mybb Mybb 1.8.2
Mybb Mybb 1.8.3
Mybb Mybb 1.8.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »