Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
7.7
CVSSv3
CVE-2017-7566
MyBB prior to 1.8.11 allows remote malicious users to bypass an SSRF protection mechanism.
Mybb Mybb
4.3
CVSSv3
CVE-2018-1000503
MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view posts from private forums without having the password. This attack appear to be exploitable via Subscribe to a forum through IDOR. This vulnerability appears to h...
Mybb Mybb
7.2
CVSSv3
CVE-2019-12831
In MyBB prior to 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by t...
Mybb Mybb
NA
CVE-2015-2332
Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mybb Mybb
NA
CVE-2015-2334
Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Mybb Mybb
NA
CVE-2015-2335
A JSON library in MyBB (aka MyBulletinBoard) prior to 1.8.4 allows remote malicious users to obtain the installation path via unknown vectors.
Mybb Mybb
NA
CVE-2015-2786
Unspecified vulnerability in MyBB (aka MyBulletinBoard) prior to 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."
Mybb Mybb
5.4
CVSSv3
CVE-2021-27279
MyBB prior to 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
Mybb Mybb
6.1
CVSSv3
CVE-2020-15139
In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g....
Mybb Mybb
8.8
CVSSv3
CVE-2021-27946
SQL Injection vulnerability in MyBB prior to 1.8.26 via poll vote count. (issue 1 of 3).
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4671
unauthorized
CVE-2024-4776
CVE-2024-3407
CVE-2024-26026
CVE-2024-32888
wireless
CVE-2024-4656
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »