Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mybb vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2016-9409
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) prior to 1.8.7 and MyBB Merge System prior to 1.8.7 might allow remote malicious users to inject arbitrary web script or HTML via vectors involving pruning logs.
Mybb Mybb
Mybb Merge System
7.7
CVSSv3
CVE-2017-7566
MyBB prior to 1.8.11 allows remote malicious users to bypass an SSRF protection mechanism.
Mybb Mybb
NA
CVE-2008-0788
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and previous versions allow remote malicious users to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and ...
Mybb Mybb
8.8
CVSSv3
CVE-2021-27946
SQL Injection vulnerability in MyBB prior to 1.8.26 via poll vote count. (issue 1 of 3).
Mybb Mybb
7.2
CVSSv3
CVE-2021-27948
SQL Injection vulnerability in MyBB prior to 1.8.26 via User Groups. (issue 3 of 3).
Mybb Mybb
6.1
CVSSv3
CVE-2021-27949
Cross-site Scripting vulnerability in MyBB prior to 1.8.26 via Custom moderator tools.
Mybb Mybb
6.1
CVSSv3
CVE-2019-20225
MyBB prior to 1.8.22 allows an open redirect on login.
Mybb Mybb
5.4
CVSSv3
CVE-2017-16781
The installer in MyBB prior to 1.8.13 has XSS.
Mybb Mybb
1 EDB exploit
7.2
CVSSv3
CVE-2019-12831
In MyBB prior to 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by t...
Mybb Mybb
5.4
CVSSv3
CVE-2014-3827
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) prior to 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser acti...
Mybb Mybb
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »