Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-0788
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and previous versions allow remote malicious users to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and ...
Mybb Mybb
7.2
CVSSv3
CVE-2023-41362
MyBB prior to 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.
Mybb Mybb
1 Github repository
5.4
CVSSv3
CVE-2021-27279
MyBB prior to 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
Mybb Mybb
6.1
CVSSv3
CVE-2017-8103
In MyBB prior to 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
Mybb Mybb
NA
CVE-2015-4552
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) prior to 1.8.5 allows remote malicious users to inject arbitrary web script or HTML via the content of a post.
Mybb Mybb
6.1
CVSSv3
CVE-2023-46251
MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the vi...
Mybb Mybb
7.2
CVSSv3
CVE-2018-1000502
MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance -> Task Manager -> Add New Task) that can result in Allows Local File Inclusion on modern PHP versions and Remote File Inclusion on ancient PHP versions. This attack appear to be e...
Mybb Mybb
6.1
CVSSv3
CVE-2019-20225
MyBB prior to 1.8.22 allows an open redirect on login.
Mybb Mybb
9.8
CVSSv3
CVE-2020-22612
Installer RCE on settings file write in MyBB prior to 1.8.22.
Mybb Mybb
NA
CVE-2008-3069
Multiple cross-site scripting (XSS) vulnerabilities in MyBB prior to 1.2.13 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters to (1) portal.php and (2) inc/functions_post.php.
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »