Mybb

Mybb

140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 17.04.2025 00:00:00
  • Zuletzt bearbeitet 25.04.2025 16:27:20

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 20.11.2024 21:15:08
  • Zuletzt bearbeitet 08.12.2025 16:15:49

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by t...

  • EPSS 0.2%
  • Veröffentlicht 01.05.2024 07:15:38
  • Zuletzt bearbeitet 30.06.2025 15:03:32

MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolve...

  • EPSS 0.11%
  • Veröffentlicht 01.05.2024 07:15:38
  • Zuletzt bearbeitet 30.06.2025 15:10:32

MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result in a Server-Side Request Forgery (SSRF) vulnerability. The Configuration File's _Disallowed Remote A...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 06.11.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 08:26:57

Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.

  • EPSS 0.54%
  • Veröffentlicht 06.11.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 08:28:10

MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a vict...

  • EPSS 0.09%
  • Veröffentlicht 01.09.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:19

Installer RCE on settings file write in MyBB before 1.8.22.

  • EPSS 22.03%
  • Veröffentlicht 29.08.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:21:09

MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

  • EPSS 0.13%
  • Veröffentlicht 22.05.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:08

In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

  • EPSS 0.98%
  • Veröffentlicht 03.01.2023 20:15:10
  • Zuletzt bearbeitet 10.04.2025 16:15:26

MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.