Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb mybb vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2016-9421
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 might allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
Mybb Merge System
6.1
CVSSv3
CVE-2018-19201
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB prior to 1.8.20 allows remote malicious users to inject JavaScript via the 'username' parameter.
Mybb Mybb
6.1
CVSSv3
CVE-2018-19202
A reflected XSS vulnerability in index.php in MyBB 1.8.x up to and including 1.8.19 allows remote malicious users to inject JavaScript via the 'upsetting[bburl]' parameter.
Mybb Mybb
NA
CVE-2015-2333
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
5.4
CVSSv3
CVE-2023-45556
Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local malicious user to execute arbitrary code via the theme Name parameter in the theme management component.
Mybb Mybb
5.4
CVSSv3
CVE-2014-3826
Cross-site scripting (XSS) vulnerability in MyBB prior to 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.
Mybb Mybb
5.4
CVSSv3
CVE-2014-3827
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) prior to 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser acti...
Mybb Mybb
NA
CVE-2015-2149
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) prior to 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types modul...
Mybb Mybb
NA
CVE-2015-2352
The cache handler in MyBB (aka MyBulletinBoard) prior to 1.8.4 does not properly check the encoding of input to the var_export function, which allows malicious users to have an unspecified impact via unknown vectors.
Mybb Mybb
NA
CVE-2008-0383
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and previous versions allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter ...
Mybb Mybb
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »