Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2021-27946
SQL Injection vulnerability in MyBB prior to 1.8.26 via poll vote count. (issue 1 of 3).
Mybb Mybb
383
VMScore
CVE-2020-15139
In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g....
Mybb Mybb
312
VMScore
CVE-2014-3827
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) prior to 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser acti...
Mybb Mybb
383
VMScore
CVE-2021-27889
Cross-site Scripting (XSS) vulnerability in MyBB prior to 1.8.26 via Nested Auto URL when parsing messages.
Mybb Mybb
1 Github repository
605
VMScore
CVE-2021-27890
SQL Injection vulnerablity in MyBB prior to 1.8.26 via theme properties included in theme XML files.
Mybb Mybb
1 Github repository
578
VMScore
CVE-2021-27947
SQL Injection vulnerability in MyBB prior to 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
Mybb Mybb
578
VMScore
CVE-2021-27948
SQL Injection vulnerability in MyBB prior to 1.8.26 via User Groups. (issue 3 of 3).
Mybb Mybb
383
VMScore
CVE-2021-27949
Cross-site Scripting vulnerability in MyBB prior to 1.8.26 via Custom moderator tools.
Mybb Mybb
NA
CVE-2022-39265
MyBB is a free and open source forum software. The _Mail Settings_ ? Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remot...
Mybb Mybb
605
VMScore
CVE-2008-0788
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and previous versions allow remote malicious users to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and ...
Mybb Mybb
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »