PatchSiren cyber security CVE debrief
CVE-2016-9421 Mybb CVE debrief
CVE-2016-9421 describes a cross-site scripting issue in the Users module of the MyBB Admin control panel. NVD rates it CVSS 3.0 6.1 (Medium) with network access, no privileges required, and user interaction required. The affected products listed in NVD are MyBB and MyBB Merge System through 1.8.7, and the vendor release notes for 1.8.8 indicate the fix was available in that release line.
- Vendor
- Mybb
- Product
- Merge System
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-31
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators running MyBB or MyBB Merge System 1.8.7 or earlier should care, especially anyone exposing the admin control panel to multiple trusted users or using workflows where ACP content can be influenced by lower-trust input.
Technical summary
NVD identifies the weakness as CWE-79 (Cross-site Scripting). The vulnerable area is the Users module in the Admin control panel, and the record indicates that remote attackers may be able to inject arbitrary web script or HTML through unspecified vectors. The CVSS vector in NVD is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which indicates network reachability, user interaction, and potential impact to confidentiality and integrity rather than availability.
Defensive priority
Medium. The issue is publicly documented, requires user interaction, and the affected versions are limited to 1.8.7 and earlier, but it can still enable session or content compromise in the admin interface if unpatched.
Recommended defensive actions
- Upgrade MyBB and MyBB Merge System to 1.8.8 or later, as identified in the vendor release notes and NVD affected-version data.
- Review admin control panel access paths and reduce exposure to only necessary administrative users.
- Audit any custom templates, plugins, or admin-side extensions that may handle user-supplied fields in the Users module.
- Apply routine content-encoding and output-escaping checks in any custom ACP code that renders user-controlled values.
- Verify that the deployed version is no longer 1.8.7 or earlier across all instances, including merged or legacy environments.
Evidence notes
The vulnerability description and affected version range are taken from the supplied NVD-derived record. NVD lists CWE-79 and the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vendor advisory reference points to the MyBB 1.8.8 / Merge System 1.8.8 release notes dated 2016-10-17, and the CVE record was published on 2017-01-31. No exploit details are included in this debrief.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9421 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9421
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9421 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9421
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/
[email protected] - Patch, Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.