Vulnerability index

Browse CVEs

36 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mybb Downloads HIGH 7.2
CVE-2018-25248

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through …

No fix yet
Fix from $1,950 2026-04-04
My Arcade MEDIUM 6.4
CVE-2018-25249

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts throug…

No fix yet
Fix from $1,600 2026-04-04
Delete Account MEDIUM 6.1
CVE-2021-47905

MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicio…

No fix yet
Fix from $1,600 2026-01-23
Trending Widget MEDIUM 6.1
CVE-2018-25132

MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles…

No fix yet
Fix from $1,600 2026-01-23
Thread Redirect MEDIUM 6.1
CVE-2018-25116

MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can in…

No fix yet
Fix from $1,600 2026-01-23
Mybb HIGH 8.8
CVE-2023-53979

MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code…

No fix yet
Fix from $1,950 2025-12-22
Mybb MEDIUM 5.4
CVE-2023-53976

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to…

No fix yet
Fix from $1,600 2025-12-22
Mybb MEDIUM 5.4
CVE-2023-53977

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to in…

No fix yet
Fix from $1,600 2025-12-22
Mybb MEDIUM 5.4
CVE-2023-53978

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to …

No fix yet
Fix from $1,600 2025-12-22
Mybb CRITICAL 9.8
CVE-2011-10018

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2025-08-13
Mybb HIGH 7.6
CVE-2025-29457

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this be…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29458

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this bec…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29459

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of t…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29460

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this becaus…

Mitigation only
Fix from $1,950 2025-04-17
Mybb MEDIUM 5.4
CVE-2024-52702

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web script…

No fix yet
Fix from $1,600 2024-11-20
Active Threads MEDIUM 6.1
CVE-2022-28354

In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.

No fix yet
Fix from $1,600 2023-04-24
Mybb MEDIUM 5.4
CVE-2020-19048

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New…

No fix yet
Fix from $1,600 2021-08-31
Mybb MEDIUM 5.4
CVE-2020-19049

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "A…

No fix yet
Fix from $1,600 2021-08-31
Mybb MEDIUM 6.1
CVE-2019-3578

MyBB 1.8.19 has XSS in the resetpassword function.

Mitigation only
Fix from $1,600 2019-06-06
Mybb MEDIUM 5.3
CVE-2019-3579

MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that la…

Mitigation only
Fix from $1,600 2019-06-06
Ban List MEDIUM 5.4
CVE-2018-14724

In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed…

No fix yet
Fix from $1,600 2019-03-21
Trash Bin HIGH 8.8
CVE-2018-14575

Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

No fix yet
Fix from $1,950 2019-03-21
Mybb MEDIUM 6.1
CVE-2018-15596

An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://loca…

No fix yet
Fix from $1,600 2018-08-28
Mybb MEDIUM 6.1
CVE-2018-10678

MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers…

Mitigation only
Fix from $1,600 2018-05-13
Mybb MEDIUM 5.4
CVE-2018-6844

MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.

Mitigation only
Fix from $1,600 2018-02-08
Ajax Forum Stat HIGH 7.5
CVE-2013-6936

Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers…

No fix yet
Fix from $1,950 2013-12-04
Mybb HIGH 7.5
CVE-2012-5909

SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL comm…

No fix yet
Fix from $1,950 2012-11-17
Mybb MEDIUM 5.0
CVE-2011-3759

MyBB (aka MyBulletinBoard) 1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the install…

No fix yet
Fix from $1,600 2011-09-23
Mybb MEDIUM 6.5
CVE-2009-4449

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery…

No fix yet
Fix from $1,600 2009-12-29
Mybb MEDIUM 6.8
CVE-2008-7082

MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) d…

Mitigation only
Fix from $1,600 2009-08-25