Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybulletinboard mybulletinboard vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2015-2333
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
6.8
CVSSv2
CVE-2010-4627
Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) prior to 1.4.12 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Mybb Mybb 1.2.10
Mybb Mybb 1.2.8
Mybb Mybb 1.4.3
Mybb Mybb 1.04
Mybb Mybb 1.1.1
Mybb Mybb 1.1.3
Mybb Mybb 1.2.2
Mybb Mybb 1.2.9
Mybb Mybb 1.4.8
Mybb Mybb 1.2.1
Mybb Mybb 1.01
Mybb Mybb 1.1.6
Mybb Mybb 1.2.6
Mybb Mybb 1.4.0
Mybb Mybb 1.2.0
Mybb Mybb 1.4.9
Mybb Mybb 1.02
Mybb Mybb 1.2.5
Mybb Mybb 1.4.2
Mybb Mybb 1.1.8
Mybb Mybb 1.2.11
Mybb Mybb 1.1.5
7.5
CVSSv2
CVE-2014-9240
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x prior to 1.8.2 allows remote malicious users to execute arbitrary SQL commands via the question_id parameter in a do_register action.
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
1 EDB exploit
5
CVSSv2
CVE-2016-9411
The Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 allows remote malicious users to obtain the installation path via vectors involving sending mails.
Mybb Mybb
Mybb Merge System
5
CVSSv2
CVE-2016-9415
MyBB (aka MyBulletinBoard) prior to 1.8.8 on Windows and MyBB Merge System prior to 1.8.8 on Windows allow remote malicious users to overwrite arbitrary CSS files via vectors related to "style import."
Mybb Merge System
Mybb Mybb
5.8
CVSSv2
CVE-2016-9417
The fetch_remote_file function in MyBB (aka MyBulletinBoard) prior to 1.8.8 and MyBB Merge System prior to 1.8.8 allows remote malicious users to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
Mybb Merge System
Mybb Mybb
5
CVSSv2
CVE-2015-8977
MyBB (aka MyBulletinBoard) prior to 1.6.18 and 1.8.x prior to 1.8.6 and MyBB Merge System prior to 1.8.6 allow remote malicious users to obtain the installation path via vectors involving error log files.
Mybb Mybb 1.8.1
Mybb Mybb 1.8.0
Mybb Mybb 1.8.3
Mybb Mybb 1.8.5
Mybb Mybb 1.8.4
Mybb Merge System
Mybb Mybb 1.8.2
Mybb Mybb
4.3
CVSSv2
CVE-2009-4813
Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote malicious users to inject arbitrary web script or HTML via the username parameter in a donate action.
Mybboard Mybb 1.4.10
1 EDB exploit
5
CVSSv2
CVE-2008-4929
MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote malicious users to read these files by guessing filenames.
Mybb Mybb 1.4.2
7.5
CVSSv2
CVE-2016-9402
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Mybb Mybb
Mybb Merge System
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2018-25103
CVE-2024-36279
CVE-2024-38457
elevation of privilege
CVE-2024-27801
CVE-2024-30103
NULL pointer dereference
CVE-2024-6057
XML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »