Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb mybb vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-5248
Cross-site scripting (XSS) vulnerability in MyBB prior to 1.6.15 allows remote malicious users to inject arbitrary web script or HTML via vectors related to video MyCode.
Mybb Mybb 1.6.4
Mybb Mybb 1.6.10
Mybb Mybb 1.6.1
Mybb Mybb 1.6.11
Mybb Mybb 1.6.7
Mybb Mybb 1.6.0
Mybb Mybb 1.6.9
Mybb Mybb 1.6.6
Mybb Mybb 1.6.13
Mybb Mybb 1.6.3
Mybb Mybb 1.6.8
Mybb Mybb
Mybb Mybb 1.6.12
Mybb Mybb 1.6.5
Mybb Mybb 1.6.2
NA
CVE-2014-1840
Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.
Mybb Mybb 1.6.4
Mybb Mybb 1.6.10
Mybb Mybb 1.6.1
Mybb Mybb 1.6.11
Mybb Mybb 1.6.7
Mybb Mybb 1.6.0
Mybb Mybb 1.6.9
Mybb Mybb 1.6.6
Mybb Mybb
Mybb Mybb 1.6.3
Mybb Mybb 1.6.8
Mybb Mybb 1.6.5
Mybb Mybb 1.6.2
8.3
CVSSv3
CVE-2015-8973
xmlhttp.php in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allows remote malicious users to bypass intended access restrictions via vectors related to the forum password.
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb 1.8.3
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Merge System
Mybb Mybb 1.8.2
Mybb Mybb
7.5
CVSSv3
CVE-2015-8977
MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allow remote malicious users to obtain the installation path via vectors involving error log files.
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb 1.8.3
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Merge System
Mybb Mybb 1.8.2
Mybb Mybb
10
CVSSv3
CVE-2015-8974
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allows remote malicious users to execute arbitrary SQL commands via unspecified vector...
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb 1.8.3
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Merge System
Mybb Mybb 1.8.2
Mybb Mybb
6.1
CVSSv3
CVE-2015-8976
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 might allow remote malicious users to inject arbitrary web script or HTML via vectors related to "old upgrade files."
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb 1.8.3
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Merge System 1.8.5
Mybb Mybb 1.8.2
Mybb Mybb
6.1
CVSSv3
CVE-2015-8975
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 might allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb 1.8.3
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Merge System 1.8.5
Mybb Mybb 1.8.2
Mybb Mybb
NA
CVE-2006-0218
Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) prior to 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and pro...
Mybb Mybb 1.0
Mybb Mybb
Mybb Mybb 1.00
NA
CVE-2005-4199
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) prior to 1.0 allow remote malicious users to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcodebuttons in an opt...
Mybb Mybb 1.0
Mybb Mybb
NA
CVE-2014-9240
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x prior to 1.8.2 allows remote malicious users to execute arbitrary SQL commands via the question_id parameter in a do_register action.
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
server-side request forgery
CVE-2024-30067
CVE-2024-5553
CVE-2024-30095
IDOR
CVE-2024-35252
CVE-2024-23692
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »