Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb mybb vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2016-9420
MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allow remote malicious users to have unspecified impact via vectors related to "loose comparison false positives."
Mybb Mybb
Mybb Merge System
NA
CVE-2022-43707
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote malicious users to inject HTML via user input or stored data
Mybb Mybb
NA
CVE-2022-43708
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow malicious users to inject HTML by persuading the user to upload a file with specially crafted name
Mybb Mybb
NA
CVE-2022-43709
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.
Mybb Mybb
4.3
CVSSv2
CVE-2018-19201
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB prior to 1.8.20 allows remote malicious users to inject JavaScript via the 'username' parameter.
Mybb Mybb
4.3
CVSSv2
CVE-2018-19202
A reflected XSS vulnerability in index.php in MyBB 1.8.x up to and including 1.8.19 allows remote malicious users to inject JavaScript via the 'upsetting[bburl]' parameter.
Mybb Mybb
4.3
CVSSv2
CVE-2016-9419
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
3.5
CVSSv2
CVE-2021-41866
MyBB prior to 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
Mybb Mybb
4.3
CVSSv2
CVE-2020-15139
In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g....
Mybb Mybb
6.8
CVSSv2
CVE-2008-0788
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and previous versions allow remote malicious users to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and ...
Mybb Mybb
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »