Mybb

Mybb

136 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Published 06.11.2023 22:15:07
  • Last modified 21.11.2024 08:26:57

Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.

  • EPSS 0.54%
  • Published 06.11.2023 18:15:08
  • Last modified 21.11.2024 08:28:10

MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a vict...

  • EPSS 0.09%
  • Published 01.09.2023 16:15:07
  • Last modified 21.11.2024 05:13:19

Installer RCE on settings file write in MyBB before 1.8.22.

  • EPSS 22.03%
  • Published 29.08.2023 16:15:09
  • Last modified 21.11.2024 08:21:09

MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

  • EPSS 0.13%
  • Published 22.05.2023 19:15:10
  • Last modified 21.11.2024 07:55:08

In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

  • EPSS 3.36%
  • Published 03.01.2023 20:15:10
  • Last modified 10.04.2025 16:15:26

MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.

  • EPSS 0.11%
  • Published 22.11.2022 00:15:12
  • Last modified 29.04.2025 15:15:50

MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name

  • EPSS 0.09%
  • Published 22.11.2022 00:15:12
  • Last modified 29.04.2025 14:15:22

MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.

  • EPSS 0.1%
  • Published 22.11.2022 00:15:10
  • Last modified 29.04.2025 15:15:50

MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data

Exploit
  • EPSS 2.54%
  • Published 06.10.2022 18:16:12
  • Last modified 21.11.2024 07:17:54

MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive i...