Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2019-12831
In MyBB prior to 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by t...
Mybb Mybb
6.1
CVSSv3
CVE-2016-9419
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
6.1
CVSSv3
CVE-2023-28467
In MyBB prior to 1.8.34, there is XSS in the User CP module via the user email field.
Mybb Mybb
5.4
CVSSv3
CVE-2018-17128
A Persistent XSS issue exists in the Visual Editor in MyBB prior to 1.8.19 via a Video MyCode.
Mybb Mybb
1 EDB exploit
8.8
CVSSv3
CVE-2021-27890
SQL Injection vulnerablity in MyBB prior to 1.8.26 via theme properties included in theme XML files.
Mybb Mybb
1 Github repository
7.2
CVSSv3
CVE-2021-43281
MyBB prior to 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported ty...
Mybb Mybb
NA
CVE-2008-0383
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and previous versions allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter ...
Mybb Mybb
1 EDB exploit
8.8
CVSSv3
CVE-2021-27946
SQL Injection vulnerability in MyBB prior to 1.8.26 via poll vote count. (issue 1 of 3).
Mybb Mybb
NA
CVE-2015-2332
Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
NA
CVE-2015-2333
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »