Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-20225
MyBB prior to 1.8.22 allows an open redirect on login.
Mybb Mybb
NA
CVE-2007-0689
MyBB 1.2.4 allows remote malicious users to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error messa...
Mybb Mybb
NA
CVE-2015-4552
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) prior to 1.8.5 allows remote malicious users to inject arbitrary web script or HTML via the content of a post.
Mybb Mybb
6.1
CVSSv3
CVE-2023-46251
MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the vi...
Mybb Mybb
NA
CVE-2015-2332
Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
NA
CVE-2015-2335
A JSON library in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to obtain the installation path via unknown vectors.
Mybb Mybb
NA
CVE-2015-2333
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
NA
CVE-2015-2334
Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Mybb Mybb
NA
CVE-2015-2352
The cache handler in MyBB (aka MyBulletinBoard) prior to 1.8.4 does not properly check the encoding of input to the var_export function, which allows malicious users to have an unspecified impact via unknown vectors.
Mybb Mybb
6.1
CVSSv3
CVE-2022-43707
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote malicious users to inject HTML via user input or stored data
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »