Mybb

Mybb

136 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.24%
  • Published 15.03.2021 17:15:22
  • Last modified 21.11.2024 05:58:42

Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.

Exploit
  • EPSS 0.38%
  • Published 22.02.2021 20:15:13
  • Last modified 21.11.2024 05:57:45

MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).

  • EPSS 0.59%
  • Published 10.08.2020 22:15:14
  • Last modified 21.11.2024 05:04:55

In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visu...

  • EPSS 0.14%
  • Published 11.02.2020 19:15:10
  • Last modified 21.11.2024 02:08:56

Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.

  • EPSS 0.19%
  • Published 11.02.2020 19:15:10
  • Last modified 21.11.2024 02:08:56

Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users mod...

  • EPSS 0.24%
  • Published 02.01.2020 15:15:12
  • Last modified 21.11.2024 04:38:14

MyBB before 1.8.22 allows an open redirect on login.

Exploit
  • EPSS 0.35%
  • Published 15.06.2019 18:29:00
  • Last modified 21.11.2024 04:23:40

In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.

Exploit
  • EPSS 0.52%
  • Published 15.06.2019 18:29:00
  • Last modified 21.11.2024 04:23:40

In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML ...

  • EPSS 0.23%
  • Published 06.06.2019 19:29:00
  • Last modified 30.06.2025 16:52:10

MyBB 1.8.19 has XSS in the resetpassword function.

  • EPSS 0.26%
  • Published 06.06.2019 19:29:00
  • Last modified 30.06.2025 16:51:43

MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter.