PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-9421 Mybb CVE debrief

CVE-2016-9421 describes a cross-site scripting issue in the Users module of the MyBB Admin control panel. NVD rates it CVSS 3.0 6.1 (Medium) with network access, no privileges required, and user interaction required. The affected products listed in NVD are MyBB and MyBB Merge System through 1.8.7, and the vendor release notes for 1.8.8 indicate the fix was available in that release line.

Vendor
Mybb
Product
Merge System
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2026-05-13
Advisory published
2017-01-31
Advisory updated
2026-05-13

Who should care

Administrators and operators running MyBB or MyBB Merge System 1.8.7 or earlier should care, especially anyone exposing the admin control panel to multiple trusted users or using workflows where ACP content can be influenced by lower-trust input.

Technical summary

NVD identifies the weakness as CWE-79 (Cross-site Scripting). The vulnerable area is the Users module in the Admin control panel, and the record indicates that remote attackers may be able to inject arbitrary web script or HTML through unspecified vectors. The CVSS vector in NVD is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which indicates network reachability, user interaction, and potential impact to confidentiality and integrity rather than availability.

Defensive priority

Medium. The issue is publicly documented, requires user interaction, and the affected versions are limited to 1.8.7 and earlier, but it can still enable session or content compromise in the admin interface if unpatched.

Recommended defensive actions

  • Upgrade MyBB and MyBB Merge System to 1.8.8 or later, as identified in the vendor release notes and NVD affected-version data.
  • Review admin control panel access paths and reduce exposure to only necessary administrative users.
  • Audit any custom templates, plugins, or admin-side extensions that may handle user-supplied fields in the Users module.
  • Apply routine content-encoding and output-escaping checks in any custom ACP code that renders user-controlled values.
  • Verify that the deployed version is no longer 1.8.7 or earlier across all instances, including merged or legacy environments.

Evidence notes

The vulnerability description and affected version range are taken from the supplied NVD-derived record. NVD lists CWE-79 and the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vendor advisory reference points to the MyBB 1.8.8 / Merge System 1.8.8 release notes dated 2016-10-17, and the CVE record was published on 2017-01-31. No exploit details are included in this debrief.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-9421 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-9421

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-9421 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9421

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.