Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Last User Threads MEDIUM 6.1
CVE-2018-25250

MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scr…

Fix: after 1.2
Fix from $1,600 2026-04-04
Mybb Downloads HIGH 7.2
CVE-2018-25248

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through …

No fix yet
Fix from $1,950 2026-04-04
My Arcade MEDIUM 6.4
CVE-2018-25249

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts throug…

No fix yet
Fix from $1,600 2026-04-04
Thankyou\/like System MEDIUM 6.1
CVE-2018-25247

MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread s…

Fix: after 3.0.0
Fix from $1,600 2026-04-04
Delete Account MEDIUM 6.1
CVE-2021-47905

MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicio…

No fix yet
Fix from $1,600 2026-01-23
Trending Widget MEDIUM 6.1
CVE-2018-25132

MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles…

No fix yet
Fix from $1,600 2026-01-23
Thread Redirect MEDIUM 6.1
CVE-2018-25116

MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can in…

No fix yet
Fix from $1,600 2026-01-23
Mybb HIGH 8.8
CVE-2023-53979

MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code…

No fix yet
Fix from $1,950 2025-12-22
Mybb MEDIUM 5.4
CVE-2023-53976

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to…

No fix yet
Fix from $1,600 2025-12-22
Mybb MEDIUM 5.4
CVE-2023-53977

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to in…

No fix yet
Fix from $1,600 2025-12-22
Mybb MEDIUM 5.4
CVE-2023-53978

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to …

No fix yet
Fix from $1,600 2025-12-22
Mybb CRITICAL 9.8
CVE-2011-10018

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2025-08-13
Mybb HIGH 7.2
CVE-2025-48940

MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attac…

Fix: 1.8.39+
Fix from $1,950 2025-06-02
Mybb MEDIUM 5.3
CVE-2025-48941

MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows atta…

Fix: 1.8.39+
Fix from $1,600 2025-06-02
Mybb HIGH 7.6
CVE-2025-29457

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this be…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29458

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this bec…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29459

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of t…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29460

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this becaus…

Mitigation only
Fix from $1,950 2025-04-17
Mybb MEDIUM 5.4
CVE-2024-52702

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web script…

No fix yet
Fix from $1,600 2024-11-20
Mybb MEDIUM 5.0
CVE-2024-23336

MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result…

Fix: 1.8.38+
Fix from $1,600 2024-05-01
Mybb MEDIUM 5.4
CVE-2023-45556

Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the…

Fix: 1.8.37+
Fix from $1,600 2023-11-06
Mybb MEDIUM 6.1
CVE-2023-46251

MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering…

Fix: 1.8.37+
Fix from $1,600 2023-11-06
Mybb CRITICAL 9.8
CVE-2020-22612

Installer RCE on settings file write in MyBB before 1.8.22.

Fix: 1.8.22+
Fix from $2,300 2023-09-01
Mybb HIGH 7.2
CVE-2023-41362

MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some vali…

Fix: 1.8.36+
Fix from $1,950 2023-08-29
Mybb MEDIUM 6.1
CVE-2023-28467

In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

Fix: 1.8.34+
Fix from $1,600 2023-05-22
Active Threads MEDIUM 6.1
CVE-2022-28354

In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.

No fix yet
Fix from $1,600 2023-04-24
Mybb HIGH 7.2
CVE-2022-45867

MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve loca…

Fix: 1.8.33+
Fix from $1,950 2023-01-03
Mybb MEDIUM 6.1
CVE-2022-43708

MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persu…

Fix: 1.8.32+
Fix from $1,600 2022-11-22
Mybb MEDIUM 6.1
CVE-2022-43707

MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user inp…

Fix: 1.8.32+
Fix from $1,600 2022-11-22
Mybb HIGH 7.2
CVE-2022-39265

MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i…

Fix: 1.8.31+
Fix from $1,950 2022-10-06