CVE-2026-45118
- EPSS 0.38%
- Veröffentlicht 18.08.2026 15:55:27
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target fr...
CVE-2026-45117
- EPSS 0.79%
- Veröffentlicht 18.08.2026 15:53:29
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execut...
CVE-2026-45129
- EPSS 0.14%
- Veröffentlicht 18.08.2026 15:53:03
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Ad...
CVE-2026-45124
- EPSS 0.25%
- Veröffentlicht 18.08.2026 15:52:31
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark...
CVE-2026-45120
- EPSS 0.22%
- Veröffentlicht 18.08.2026 15:52:03
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The private-event check...
CVE-2026-47245
- EPSS 0.27%
- Veröffentlicht 18.08.2026 15:51:33
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate reciprocal buddy-list updates correctly. The usercp.php?action=do_editlists delete handler removes the selected entry from the act...
CVE-2026-45734
- EPSS 0.4%
- Veröffentlicht 18.08.2026 15:51:07
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass CAPTCHA controls through challenge replay. The successful validation paths in c...
CVE-2026-45125
- EPSS 0.3%
- Veröffentlicht 18.08.2026 15:50:38
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the...
CVE-2026-45122
- EPSS 0.25%
- Veröffentlicht 18.08.2026 15:50:02
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to...
CVE-2026-45119
- EPSS 0.13%
- Veröffentlicht 18.08.2026 15:49:14
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially crafted URL. The d...