Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2017-16780EPSS 6%
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
Mybb
after 1.8.12
MEDIUM 5.4
CVE-2017-16781
The installer in MyBB before 1.8.13 has XSS.
Mybb
after 1.8.12
MEDIUM 6.1
CVE-2017-8103
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
Mybb
after 1.8.10
MEDIUM 5.3
CVE-2017-8104
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
Mybb
after 1.8.10
HIGH 7.7
CVE-2017-7566
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
Mybb
after 1.8.10
CRITICAL 9.8
CVE-2016-9402
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote a…
Merge System
after 1.8.6
CRITICAL 9.8
CVE-2016-9403
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leve…
Merge System
after 1.8.6
CRITICAL 9.8
CVE-2016-9412
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low admi…
Merge System
after 1.8.6
CRITICAL 9.8
CVE-2016-9416
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote att…
Merge System
after 1.8.7
CRITICAL 9.8
CVE-2016-9420
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "…
Merge System
after 1.8.7
HIGH 7.5
CVE-2016-9410
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via …
Merge System
after 1.8.6
HIGH 7.5
CVE-2016-9414
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missi…
Merge System
after 1.8.6
HIGH 7.5
CVE-2016-9415
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS fi…
Merge System
after 1.8.7
HIGH 7.5
CVE-2016-9418
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive inf…
Merge System
after 1.8.7
HIGH 7.4
CVE-2016-9417
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct serve…
Merge System
after 1.8.7
MEDIUM 6.5
CVE-2016-9413
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to conduct clickjacking…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9404
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers t…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9405
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might all…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9406
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 migh…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9407
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers t…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9408
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9409
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 mig…
Merge System
after 1.8.6
MEDIUM 6.1
CVE-2016-9419
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 all…
Mybb
after 1.8.7
MEDIUM 6.1
CVE-2016-9421
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge Sys…
Merge System
after 1.8.7
MEDIUM 5.3
CVE-2016-9411
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installat…
Merge System
after 1.8.6
CRITICAL 10.0
CVE-2015-8974
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.…
Merge System
after 1.8.5
HIGH 8.3
CVE-2015-8973
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass i…
Merge System
after 1.8.5
HIGH 7.5
CVE-2015-8977
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation …
Merge System
after 1.8.5
MEDIUM 6.1
CVE-2015-8975
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge Syste…
Merge System
after 1.6.17
MEDIUM 6.1
CVE-2015-8976
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might …
Merge System
after 1.6.17