Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-2149
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) prior to 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types modul...
Mybb Mybb
NA
CVE-2008-3069
Multiple cross-site scripting (XSS) vulnerabilities in MyBB prior to 1.2.13 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters to (1) portal.php and (2) inc/functions_post.php.
Mybb Mybb
NA
CVE-2008-3071
Directory traversal vulnerability in inc/class_language.php in MyBB prior to 1.2.13 has unknown impact and attack vectors related to the $language variable.
Mybb Mybb
5.3
CVSSv3
CVE-2017-8104
In MyBB prior to 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
Mybb Mybb
7.2
CVSSv3
CVE-2022-24734
MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change S...
Mybb Mybb
2 Github repositories
5.4
CVSSv3
CVE-2018-17128
A Persistent XSS issue exists in the Visual Editor in MyBB prior to 1.8.19 via a Video MyCode.
Mybb Mybb
1 EDB exploit
8.7
CVSSv3
CVE-2019-12830
In MyBB prior to 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.
Mybb Mybb
5.4
CVSSv3
CVE-2014-3826
Cross-site scripting (XSS) vulnerability in MyBB prior to 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.
Mybb Mybb
NA
CVE-2008-3070
Unspecified vulnerability in inc/datahandler/user.php in MyBB prior to 1.2.13 has unknown impact and attack vectors related to the $user['language'] variable, probably related to SQL injection.
Mybb Mybb
6.1
CVSSv3
CVE-2017-8103
In MyBB prior to 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »