PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-9404 Mybb CVE debrief

CVE-2016-9404 is a cross-site scripting (XSS) issue affecting MyBB and MyBB Merge System versions before 1.8.7. The NVD record describes the issue as allowing remote attackers to inject arbitrary web script or HTML through vectors related to login. Because the attack requires user interaction and can impact both confidentiality and integrity, it is a meaningful web-application risk even though the CVSS score is in the medium range.

Vendor
Mybb
Product
Merge System
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2026-05-13
Advisory published
2017-01-31
Advisory updated
2026-05-13

Who should care

Administrators and maintainers running MyBB or MyBB Merge System before 1.8.7, especially sites exposing login flows to untrusted users. Security teams responsible for forum platforms and web applications that embed or integrate these components should also review exposure.

Technical summary

The NVD record classifies the weakness as CWE-79 (cross-site scripting) and assigns CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. That combination indicates a network-reachable issue that does not require privileges, but does require user interaction and can affect security boundaries. The affected CPEs in the record are MyBB and MyBB Merge System through version 1.8.6, with the issue described as tied to login-related vectors.

Defensive priority

Medium priority. The issue is publicly documented, affects commonly deployed forum software, and can lead to script or HTML injection in a user-facing authentication path. Remediation should be scheduled promptly if affected versions are still in use.

Recommended defensive actions

  • Upgrade MyBB and MyBB Merge System to version 1.8.7 or later.
  • Review login-related pages and templates for XSS exposure if upgrading is delayed.
  • Validate that any reverse proxies, WAF rules, or templating changes do not reintroduce script injection risks.
  • Check for any custom modifications around authentication or merge workflows that may need to be re-tested after patching.
  • Confirm all exposed instances match the vulnerable version range in the NVD CPE criteria (through 1.8.6).

Evidence notes

All claims are limited to the supplied CVE/NVD metadata and the referenced vendor or advisory links listed in the source corpus. The record states the weakness type (CWE-79), affected products/versions, CVSS vector, and the login-related XSS description. No exploit details or unverified impact statements are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-9404 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-9404

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-9404 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9404

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.