Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mybb HIGH 10.0
CVE-2015-2786

Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to …

Fix: after 1.8.3
Fix from $1,950 2015-03-29
Mybb HIGH 7.5
CVE-2015-2352

The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows a…

Fix: after 1.8.3
Fix from $1,950 2015-03-19
Mybb MEDIUM 5.0
CVE-2015-2335

A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

Fix: after 1.8.3
Fix from $1,600 2015-03-18
Mybb MEDIUM 6.8
CVE-2015-2334

Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attac…

Fix: after 1.8.3
Fix from $1,600 2015-03-18
Mybb HIGH 7.5
CVE-2014-9240

SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands …

Patch available
Fix from $1,950 2014-12-03
Ajax Forum Stat HIGH 7.5
CVE-2013-6936

Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers…

No fix yet
Fix from $1,950 2013-12-04
Mybb HIGH 7.5
CVE-2012-5909

SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL comm…

No fix yet
Fix from $1,950 2012-11-17
Mybb HIGH 10.0
CVE-2011-5133

Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."

Fix: after 1.6.4
Fix from $1,950 2012-08-30
Mybb MEDIUM 6.8
CVE-2011-5131

Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for…

Fix: after 1.6.4
Fix from $1,600 2012-08-30
Mybb HIGH 7.5
CVE-2010-5096EPSS 6%

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the ke…

Fix: after 1.6.0
Fix from $1,950 2012-08-13
Mybb HIGH 7.5
CVE-2012-2325

SQL injection vulnerability in the User Inline Moderation feature in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows …

Fix: after 1.6.6
Fix from $1,950 2012-08-13
Mybb MEDIUM 5.0
CVE-2012-2327

MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the i…

Fix: after 1.6.6
Fix from $1,600 2012-08-13
Mybb HIGH 7.5
CVE-2012-2324

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via u…

Fix: after 1.6.6
Fix from $1,950 2012-08-13
Mybb MEDIUM 5.0
CVE-2011-3759

MyBB (aka MyBulletinBoard) 1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the install…

No fix yet
Fix from $1,600 2011-09-23
Mybb MEDIUM 6.8
CVE-2010-4627

Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote attackers to hijack the auth…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Mybb MEDIUM 5.1
CVE-2010-4626

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easi…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Mybb MEDIUM 5.0
CVE-2010-4625

MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows rem…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Mybb MEDIUM 5.0
CVE-2010-4628

member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to c…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Mybb MEDIUM 5.0
CVE-2010-4629

MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a deni…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Mybb MEDIUM 6.5
CVE-2009-4449

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery…

No fix yet
Fix from $1,600 2009-12-29
Mybb MEDIUM 5.0
CVE-2009-4448

inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU…

Patch available
Fix from $1,600 2009-12-29
Mybb MEDIUM 6.8
CVE-2008-7082

MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) d…

Mitigation only
Fix from $1,600 2009-08-25
Mybb HIGH 7.5
CVE-2008-4929

MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for r…

No fix yet
Fix from $1,950 2008-11-04
Mybb MEDIUM 5.0
CVE-2008-4930

MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded file with a nonstandard file type that contains HTML sequences, which allows re…

Mitigation only
Fix from $1,600 2008-11-04
Mybb HIGH 7.5
CVE-2008-3965

SQL injection vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.4.1 allows remote attackers to execute arbitrary SQL commands via a ce…

Fix: after 1.4.0
Fix from $1,950 2008-09-11
Mybb HIGH 7.5
CVE-2008-3967

moderation.php in MyBB (aka MyBulletinBoard) before 1.4.1 does not properly check for moderator privileges, which has unknown impact and remote attac…

Fix: after 1.4.0
Fix from $1,950 2008-09-11
Mybb HIGH 7.5
CVE-2008-3070

Unspecified vulnerability in inc/datahandler/user.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $user['language'] va…

Fix: after 1.2.12
Fix from $1,950 2008-07-08
Mybb HIGH 7.5
CVE-2008-3071

Directory traversal vulnerability in inc/class_language.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $language vari…

Fix: after 1.2.12
Fix from $1,950 2008-07-08
Mybb MEDIUM 6.8
CVE-2008-0788

Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of mode…

Fix: after 1.2.11
Fix from $1,600 2008-02-15
Mybb HIGH 7.5
CVE-2008-0383

Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1…

Fix: after 1.2.10
Fix from $1,950 2008-01-22