CVE-2026-45126
- EPSS 0.13%
- Veröffentlicht 18.08.2026 15:47:09
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with a specially ...
CVE-2026-45116
- EPSS 0.3%
- Veröffentlicht 18.08.2026 15:46:34
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only p...
CVE-2026-45115
- EPSS 0.29%
- Veröffentlicht 18.08.2026 15:46:00
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore lis...
CVE-2026-45121
- EPSS 0.25%
- Veröffentlicht 18.08.2026 15:45:29
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected...
CVE-2026-46482
- EPSS 0.33%
- Veröffentlicht 18.08.2026 15:44:59
- Zuletzt bearbeitet 08.09.2026 21:02:26
### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value. [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](https://www.first...
CVE-2026-45123
- EPSS 0.27%
- Veröffentlicht 18.08.2026 15:44:26
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IP...
CVE-2026-45128
- EPSS 0.13%
- Veröffentlicht 18.08.2026 15:43:41
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a specially craf...
CVE-2026-45127
- EPSS 0.13%
- Veröffentlicht 18.08.2026 15:38:41
- Zuletzt bearbeitet 08.09.2026 21:02:26
MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially crafted URL. The ...
CVE-2026-58054
- EPSS 0.27%
- Veröffentlicht 28.06.2026 02:16:32
- Zuletzt bearbeitet 24.07.2026 19:16:59
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the basis that the permission system allows a limited administrator to grant privileges exceeding their own authorization scope, pote...
CVE-2023-53977
- EPSS 0.23%
- Veröffentlicht 22.12.2025 21:35:35
- Zuletzt bearbeitet 27.12.2025 17:15:45
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by insertin...