PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-9408 Mybb CVE debrief

CVE-2016-9408 is a cross-site scripting issue in the MyBB Mod control panel and MyBB Merge System before 1.8.7. The NVD record says remote attackers may inject arbitrary web script or HTML through user-editing vectors, and the vulnerability is classified as CWE-79.

Vendor
Mybb
Product
Merge System
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2026-05-13
Advisory published
2017-01-31
Advisory updated
2026-05-13

Who should care

MyBB administrators, forum operators, and moderators using the Mod control panel or MyBB Merge System versions 1.8.6 and earlier should care most. Any environment where trusted staff edit users through the control panel is in scope.

Technical summary

NVD rates the issue CVSS 3.0 6.1/Medium with vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. That means it is network reachable, requires a user to interact, and can affect the browser-side confidentiality and integrity of the session under changed scope.

Defensive priority

Medium priority. Upgrade planning should be accelerated for public-facing or heavily used forums, but this CVE is not marked as KEV in the supplied data.

Recommended defensive actions

  • Upgrade MyBB and MyBB Merge System to 1.8.7 or later.
  • Confirm that moderators and administrators are on patched builds before re-enabling the Mod control panel workflows.
  • Review any custom templates, plugins, or admin pages that render user-editing fields and ensure they safely encode untrusted content.
  • Limit Mod control panel access to trusted users and keep role-based permissions as narrow as practical.
  • Use the vendor release notes and NVD references to verify the fixed release and any migration steps before deployment.

Evidence notes

The supplied NVD record lists affected CPE ranges ending at 1.8.6 for both mybb:mybb and mybb:merge_system. It also assigns CWE-79 and CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The reference set includes MyBB 1.8.7 release notes, mailing-list posts, and a third-party advisory, which support the fix timeline and affected-version boundary.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-9408 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-9408

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-9408 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9408

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.