PatchSiren

mybb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM mybb CVE published 2026-08-18

CVE-2026-47245

A vulnerability in MyBB's User CP Buddy/Ignore List component allows for unintended modifications to a user's buddy list. Prior to version 1.8.40, the software incorrectly validates reciprocal buddy-list updates, which can lead to the removal of an unintended buddy from the target user's list. This issue arises from the incorrect use of the array_search() return value as an array key, potentially resultin [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-46482

CVE-2026-46482 is a vulnerability in the MyBB registration component that allows attackers to bypass the Security Question CAPTCHA challenge via a specially crafted value. The issue arises from the lack of proper validation for the text-based CAPTCHA, enabling unauthorized access without the challenge being correctly completed. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45734

CVE-2026-45734 MyBB CAPTCHA bypass vulnerability debrief. The MyBB forum software prior to version 1.8.40 contains a CAPTCHA bypass vulnerability. The built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass CAPTCHA controls through challenge replay. This issue allows attackers to potentially automate registration and spam, and may enable brute-force attacks [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45129

CVE-2026-45129 is a vulnerability in MyBB forum software prior to version 1.8.40, allowing same-site attackers to rotate a victim administrator's recovery codes via a specially crafted URL. The issue is fixed in version 1.8.40. This vulnerability affects MyBB administrators and security teams, who should assess exposure and update to the fixed version. The vulnerability is related to the Admin CP Recovery [truncated]

LOW mybb CVE published 2026-08-18

CVE-2026-45128

A vulnerability in MyBB forum software prior to version 1.8.40 allows same-site attackers to change a victim administrator's default user list view by embedding a specially crafted URL in the ACP Users View Manager module. The issue is fixed in version 1.8.40. This vulnerability affects MyBB deployments where administrators have access to the ACP Users View Manager module. Defenders should verify exposure [truncated]

LOW mybb CVE published 2026-08-18

CVE-2026-45127

A vulnerability in MyBB forum software prior to version 1.8.40 allows same-site attackers to create draft entries from archived entries by embedding a specially crafted URL in the ACP Mass Mail module. This issue is fixed in version 1.8.40. The vulnerability exists due to a lack of validation in the ACP Mass Mail module, which allows attackers to create draft entries from archived entries. Administrators [truncated]

LOW mybb CVE published 2026-08-18

CVE-2026-45126

A vulnerability in MyBB forum software prior to version 1.8.40 allows same-site attackers to modify registration challenge questions using a specially crafted URL, due to incorrect validation of the anti-CSRF token in the Admin CP Security Questions module. This issue enables attackers to potentially manipulate security settings, leading to unauthorized changes in the registration process. Defenders shoul [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45125

CVE-2026-45125 is a medium-severity vulnerability in MyBB forum software prior to version 1.8.40, allowing mail header injection via the Email User controller. The issue arises from improper sanitization of sender names, enabling arbitrary header injection with CRLF sequences when using the default PHP mail handler. This vulnerability is fixed in MyBB version 1.8.40.

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45124

CVE-2026-45124 MyBB forum software vulnerability allows moderators without report-management permission to mark reports as resolved due to inconsistent permission checks in the Mod CP Report Center. The issue is fixed in version 1.8.40. This vulnerability impacts MyBB forum administrators and moderators, who should assess exposure and update to version 1.8.40 or later to mitigate potential security risks. [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45123

A server-side request forgery vulnerability exists in MyBB forum software prior to version 1.8.40. The remote requests feature does not correctly handle IPv6 addresses, allowing a crafted remote target to bypass the host restriction. This issue is fixed in version 1.8.40. MyBB administrators and security teams should assess exposure and apply the patch. The vulnerability has a CVSS score of 4.3 and is con [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45122

CVE-2026-45122 is a vulnerability in MyBB forum software prior to version 1.8.40, where the calendar module fails to validate moderation permissions when moving events between calendars. A user with moderation permission for the source calendar can move an event to a calendar where they only have viewing permission. This issue is fixed in version 1.8.40.

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45121

CVE-2026-45121 MyBB forum software vulnerability allows authenticated users to access titles of calendars that are otherwise inaccessible due to inconsistent permission checks in the calendar module prior to version 1.8.40. The affected product is MyBB, a free and open source forum software. The vulnerability class is related to permission checks in the calendar module. The likely operational impact inclu [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45120

CVE-2026-45120 MyBB Calendar Module Private Event Access. The MyBB calendar module prior to version 1.8.40 does not consistently verify private event status, allowing users with viewing and moderation permissions to access and moderate private events. This issue affects MyBB users and administrators who need to assess exposure and apply updates to prevent unauthorized access to private events. The vulnera [truncated]

MEDIUM mybb CVE published 2026-08-18

CVE-2026-45119

A vulnerability in MyBB forum software prior to version 1.8.40 allows same-site attackers to alter table encoding and potentially deny service via a specially crafted URL. The issue arises from the Admin CP UTF-8 Conversion module not validating certain requests correctly. This vulnerability impacts the availability of the forum service and requires immediate attention from system administrators and secur [truncated]

CRITICAL mybb CVE published 2026-08-18

CVE-2026-45118

CVE-2026-45118 is a critical open redirect and reflected JavaScript code injection vulnerability in MyBB prior to version 1.8.40. The vulnerability exists in the Contact module, where the redirect URL or protocol is not validated correctly. This allows an attacker to use a javascript: URI as the target of the 'Click here if you don't want to wait any longer' link, enabling script execution when a victim s [truncated]

CRITICAL mybb CVE published 2026-08-18

CVE-2026-45117

A critical vulnerability was found in MyBB forum software versions 1.8.13 to 1.8.39. The installer module does not properly escape user-supplied database configuration values, allowing for PHP code injection and remote code execution when the installer is available. This issue arises from the incomplete addition of characters to the $characters argument in the addcslashes() function, introduced in MyBB 1. [truncated]

HIGH mybb CVE published 2026-08-18

CVE-2026-45116

CVE-2026-45116 MyBB forum software stored JavaScript code injection vulnerability allows attackers to inject malicious scripts due to improper validation of checkbox and multiselect profile field types. This issue, fixed in version 1.8.40, enables stored JavaScript code injection via user profile fields. MyBB users and administrators should assess exposure and prioritize upgrading to version 1.8.40 or lat [truncated]

HIGH mybb CVE published 2026-08-18

CVE-2026-45115

CVE-2026-45115 is a high-severity vulnerability in MyBB forum software prior to version 1.8.40, allowing attackers to inject JavaScript code through specially crafted usernames in the Buddy/Ignore component. The vulnerability is fixed in version 1.8.40. This issue affects MyBB installations that have not been upgraded to version 1.8.40 or later. Defenders should assess exposure and prioritize upgrading to [truncated]

MEDIUM MyBB CVE published 2026-05-16

CVE-2021-47934

CVE-2021-47934 describes multiple web application issues in MyBB Timeline Plugin 1.0: cross-site scripting through thread titles, post content, and profile fields such as Location and Bio, plus a CSRF issue in timeline.php profile actions that can be used to change a user's cover picture. The risk is highest where the plugin is installed and exposed to untrusted user input or profile interactions.

MEDIUM MyBB CVE published 2026-04-04

CVE-2018-25250

The CVE record for CVE-2018-25250 was published on 2026-04-04T14:16:21.033Z and has not been modified since then. The NVD entry is currently Analyzed. This persistent cross-site scripting vulnerability in MyBB's Last User's Threads in Profile Plugin version 1.2 allows attackers to inject malicious scripts by crafting thread subjects with script tags. These scripts execute when users visit the attacker's p [truncated]

MEDIUM MyBB CVE published 2026-04-04

CVE-2018-25249

The CVE record for CVE-2018-25249 was published on 2026-04-04T14:16:20.860Z and has not been modified since then. The NVD entry is currently Analyzed. This persistent cross-site scripting vulnerability in MyBB My Arcade Plugin 1.3 allows authenticated users to inject malicious scripts through arcade game score comments. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. The affected produ [truncated]

MEDIUM MyBB CVE published 2026-04-04

CVE-2018-25248

The MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability. This vulnerability allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php. The vulnerability has a CVSS score of 5.1 and a sever [truncated]

MEDIUM MyBB CVE published 2026-04-04

CVE-2018-25247

The MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the unsanitized subject is rendered, executing the script in the viewer's browser. This vulnerability has a CVSS score of 5.1 and is rated as MEDIUM. The vulnerability is c [truncated]

MEDIUM Mybb CVE published 2017-01-31

CVE-2016-9421

CVE-2016-9421 describes a cross-site scripting issue in the Users module of the MyBB Admin control panel. NVD rates it CVSS 3.0 6.1 (Medium) with network access, no privileges required, and user interaction required. The affected products listed in NVD are MyBB and MyBB Merge System through 1.8.7, and the vendor release notes for 1.8.8 indicate the fix was available in that release line.

CRITICAL Mybb CVE published 2017-01-31

CVE-2016-9420

CVE-2016-9420 is a critical flaw in MyBB and MyBB Merge System before 1.8.8. NVD ties the issue to "loose comparison false positives" and rates the impact as potentially severe, with network access possible without authentication or user interaction.

MEDIUM Mybb CVE published 2017-01-31

CVE-2016-9419

CVE-2016-9419 is a cross-site scripting (XSS) vulnerability in the MyBB Admin control panel and the MyBB Merge System before 1.8.8. NVD maps the issue to CWE-79 and rates it as network-reachable with user interaction required, allowing injected web script or HTML to affect confidentiality and integrity at a low level. The vendor release notes referenced in the CVE record point to MyBB 1.8.8 / Merge System [truncated]

HIGH Mybb CVE published 2017-01-31

CVE-2016-9418

CVE-2016-9418 is a Windows-specific information disclosure issue in MyBB and MyBB Merge System before 1.8.8. According to NVD, remote attackers could obtain sensitive information from ACP backups via a short-name related vector, with no privileges or user interaction required.

HIGH Mybb CVE published 2017-01-31

CVE-2016-9417

CVE-2016-9417 is a server-side request forgery (SSRF) issue in MyBB and MyBB Merge System versions before 1.8.8. The flaw is identified in the fetch_remote_file function and was assigned a HIGH severity score by NVD. The main security concern is that a remote attacker may be able to make the forum server initiate requests to attacker-influenced destinations, which can expose internal services or other net [truncated]

CRITICAL Mybb CVE published 2017-01-31

CVE-2016-9416

CVE-2016-9416 is a critical SQL injection vulnerability in MyBB’s users data handler. According to the CVE record, affected MyBB and MyBB Merge System installations before 1.8.8 can be abused by a remote attacker to execute arbitrary SQL commands.

HIGH Mybb CVE published 2017-01-31

CVE-2016-9415

CVE-2016-9415 is a high-severity integrity issue in MyBB and MyBB Merge System before 1.8.8 on Windows. A remote attacker can overwrite arbitrary CSS files through vectors tied to style import, which can alter site presentation and potentially support follow-on tampering. The public reference trail shows vendor release notes and security mailing list discussion before the CVE record was published.