Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2016-9404
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to inject arbitrary web script or HTML via vectors related to login.
Mybb Mybb
Mybb Merge System
4.3
CVSSv2
CVE-2016-9405
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
Mybb Merge System
4.3
CVSSv2
CVE-2016-9406
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Merge System
Mybb Mybb
4.3
CVSSv2
CVE-2016-9407
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to inject arbitrary web script or HTML via vectors involving Mod control panel logs.
Mybb Merge System
Mybb Mybb
7.5
CVSSv2
CVE-2016-9412
MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allow malicious users to have unspecified impact via vectors related to low adminsid and sid entropy.
Mybb Mybb
Mybb Merge System
4.3
CVSSv2
CVE-2016-9413
The Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allows remote malicious users to conduct clickjacking attacks via unspecified vectors.
Mybb Mybb
Mybb Merge System
5
CVSSv2
CVE-2016-9414
MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allow remote malicious users to obtain sensitive information by leveraging missing directory listing protection in upload directories.
Mybb Merge System
Mybb Mybb
7.5
CVSSv2
CVE-2016-9416
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Mybb Merge System
Mybb Mybb
5.8
CVSSv2
CVE-2016-9417
The fetch_remote_file function in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
Mybb Mybb
Mybb Merge System
7.5
CVSSv2
CVE-2016-9420
MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allow remote malicious users to have unspecified impact via vectors related to "loose comparison false positives."
Mybb Mybb
Mybb Merge System
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »