Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2017-8104
In MyBB prior to 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
Mybb Mybb
7.2
CVSSv3
CVE-2021-43281
MyBB prior to 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported ty...
Mybb Mybb
5.4
CVSSv3
CVE-2018-17128
A Persistent XSS issue exists in the Visual Editor in MyBB prior to 1.8.19 via a Video MyCode.
Mybb Mybb
1 EDB exploit
NA
CVE-2008-0383
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and previous versions allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter ...
Mybb Mybb
1 EDB exploit
5.4
CVSSv3
CVE-2023-45556
Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local malicious user to execute arbitrary code via the theme Name parameter in the theme management component.
Mybb Mybb
5.4
CVSSv3
CVE-2014-3827
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) prior to 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser acti...
Mybb Mybb
6.1
CVSSv3
CVE-2023-46251
MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the vi...
Mybb Mybb
6.1
CVSSv3
CVE-2022-43707
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote malicious users to inject HTML via user input or stored data
Mybb Mybb
6.1
CVSSv3
CVE-2022-43708
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow malicious users to inject HTML by persuading the user to upload a file with specially crafted name
Mybb Mybb
NA
CVE-2015-4552
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) prior to 1.8.5 allows remote malicious users to inject arbitrary web script or HTML via the content of a post.
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »