Mybb

Mybb

136 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Published 29.03.2015 21:59:03
  • Last modified 12.04.2025 10:46:40

Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."

  • EPSS 0.4%
  • Published 19.03.2015 14:59:04
  • Last modified 12.04.2025 10:46:40

The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.

  • EPSS 0.28%
  • Published 18.03.2015 14:59:04
  • Last modified 12.04.2025 10:46:40

A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

  • EPSS 0.13%
  • Published 18.03.2015 14:59:03
  • Last modified 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • EPSS 0.3%
  • Published 18.03.2015 14:59:02
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.3%
  • Published 18.03.2015 14:59:01
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploit
  • EPSS 0.3%
  • Published 18.03.2015 14:59:00
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the c...

Exploit
  • EPSS 1.02%
  • Published 03.12.2014 21:59:11
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig actio...

Exploit
  • EPSS 1.35%
  • Published 03.12.2014 21:59:10
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.

  • EPSS 0.26%
  • Published 14.08.2014 18:47:06
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.