Mybb

Mybb

136 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 80.34%
  • Published 09.03.2022 22:15:09
  • Last modified 21.11.2024 06:50:58

MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code,...

  • EPSS 0.73%
  • Published 04.11.2021 18:15:08
  • Last modified 21.11.2024 06:28:59

MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of...

  • EPSS 0.28%
  • Published 26.10.2021 22:15:08
  • Last modified 21.11.2024 06:26:55

MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.

Exploit
  • EPSS 0.15%
  • Published 31.08.2021 14:15:25
  • Last modified 21.11.2024 05:08:55

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-man...

Exploit
  • EPSS 0.14%
  • Published 31.08.2021 14:15:25
  • Last modified 21.11.2024 05:08:56

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=for...

Exploit
  • EPSS 5.71%
  • Published 15.03.2021 18:15:18
  • Last modified 21.11.2024 05:58:42

SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.

Exploit
  • EPSS 0.23%
  • Published 15.03.2021 18:15:18
  • Last modified 21.11.2024 05:58:53

SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).

  • EPSS 0.27%
  • Published 15.03.2021 18:15:18
  • Last modified 21.11.2024 05:58:53

SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).

  • EPSS 0.27%
  • Published 15.03.2021 18:15:18
  • Last modified 21.11.2024 05:58:53

SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).

  • EPSS 0.22%
  • Published 15.03.2021 18:15:18
  • Last modified 21.11.2024 05:58:53

Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.