Записи mybb
156 опубликованных записей вендора mybb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 1,3 %
- Pre-auth RCE
- 20
- С записью об исправлении
- 1,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-918 Server-Side Request Forgery (SSRF)6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
156 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2022-24734Готовый эксплойт | Remote code execution in mybbmybb · mybb · CWE-94 | Высокая7,2 | — | 77,8 % | 9 мар. 2022 г. |
43В плане | CVE-2018-17128Proof of concept | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.mybb · mybb · CWE-79 | Средняя5,4 | — | 74,8 % | 17 сент. 2018 г. |
41В плане | CVE-2017-16780Proof of concept | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.mybb · mybb · CWE-352 | Критическая9,8 | — | 5,8 % | 10 нояб. 2017 г. |
41В плане | CVE-2015-8974Эксплойта нет | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x mybb · merge system · CWE-89 | Критическая10,0 | — | 2,1 % | 31 янв. 2017 г. |
41В плане | CVE-2011-10018Готовый эксплойт | myBB 1.6.4 Backdoor Arbitrary Command Executionmybb · mybb · CWE-94 | Критическая10,0 | — | 2,0 % | 13 авг. 2025 г. |
41В плане | CVE-2011-5133Эксплойта нет | Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.mybb · mybb | Критическая10,0 | — | 1,7 % | 30 авг. 2012 г. |
40В плане | CVE-2016-9403Эксплойта нет | newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impacmybb · merge system · CWE-264 | Критическая9,8 | — | 2,6 % | 31 янв. 2017 г. |
40В плане | CVE-2016-9420Эксплойта нет | MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors relmybb · merge system · CWE-20 | Критическая9,8 | — | 2,6 % | 31 янв. 2017 г. |
40В плане | CVE-2016-9412Эксплойта нет | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related tomybb · merge system · CWE-284 | Критическая9,8 | — | 2,2 % | 31 янв. 2017 г. |
40В плане | CVE-2016-9402Эксплойта нет | SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allowmybb · merge system · CWE-89 | Критическая9,8 | — | 2,1 % | 31 янв. 2017 г. |
40В плане | CVE-2016-9416Эксплойта нет | SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows rmybb · merge system · CWE-89 | Критическая9,8 | — | 2,1 % | 31 янв. 2017 г. |
40В плане | CVE-2015-2786Эксплойта нет | Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notificationsmybb · mybb | Критическая10,0 | — | 1,4 % | 29 мар. 2015 г. |
40В плане | CVE-2006-0218Эксплойта нет | Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) adminmybb · mybb | Критическая10,0 | — | 1,2 % | 16 янв. 2006 г. |
39Наблюдать | CVE-2018-14392Proof of concept | The New Threads plugin before 1.2 for MyBB has XSS.mybb · new threads · CWE-79 | Средняя6,1 | — | 48,6 % | 18 июл. 2018 г. |
39Наблюдать | CVE-2020-22612Эксплойта нет | Installer RCE on settings file write in MyBB before 1.8.22.mybb · mybb · CWE-94 | Критическая9,8 | — | 0,7 % | 1 сент. 2023 г. |
38Наблюдать | CVE-2021-27890Proof of concept | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.mybb · mybb · CWE-89 | Высокая8,8 | — | 10,6 % | 15 мар. 2021 г. |
36Наблюдать | CVE-2021-27946Proof of concept | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.mybb · mybb · CWE-89 | Высокая8,8 | — | 4,2 % | 15 мар. 2021 г. |
36Наблюдать | CVE-2018-14575Proof of concept | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subjemybb · trash bin · CWE-79 | Высокая8,8 | — | 2,4 % | 21 мар. 2019 г. |
34Наблюдать | CVE-2019-12830Эксплойта нет | In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistentmybb · mybb · CWE-79 | Высокая8,7 | — | 1,0 % | 15 июн. 2019 г. |
34Наблюдать | CVE-2023-53979Эксплойта нет | MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilitiesmybb · mybb · CWE-22 | Высокая8,6 | — | 0,8 % | 22 дек. 2025 г. |
33Наблюдать | CVE-2015-8973Эксплойта нет | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers tomybb · merge system · CWE-284 | Высокая8,3 | — | 1,6 % | 31 янв. 2017 г. |
32Наблюдать | CVE-2010-5096Proof of concept | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands vmybb · mybb · CWE-89 | Высокая7,5 | — | 5,6 % | 13 авг. 2012 г. |
31Наблюдать | CVE-2014-9240Proof of concept | SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL mybb · mybb · CWE-89 | Высокая7,5 | — | 3,5 % | 3 дек. 2014 г. |
31Наблюдать | CVE-2013-6936Proof of concept | Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote mybb · ajax forum stat · CWE-89 | Высокая7,5 | — | 2,5 % | 4 дек. 2013 г. |
31Наблюдать | CVE-2016-9414Эксплойта нет | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveragmybb · merge system · CWE-200 | Высокая7,5 | — | 2,3 % | 31 янв. 2017 г. |
- CVE-2022-2473451В плане
Remote code execution in mybb
ВысокаяCVSS 7,2Готовый эксплойтEPSS 78 %mybb · mybb9 мар. 2022 г.
- CVE-2018-1712843В плане
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
СредняяCVSS 5,4Proof of conceptEPSS 75 %mybb · mybb17 сент. 2018 г.
- CVE-2017-1678041В плане
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
КритическаяCVSS 9,8Proof of conceptEPSS 6 %mybb · mybb10 нояб. 2017 г.
- CVE-2015-897441В плане
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mybb · merge system31 янв. 2017 г.
- CVE-2011-1001841В плане
myBB 1.6.4 Backdoor Arbitrary Command Execution
КритическаяCVSS 10,0Готовый эксплойтEPSS 2 %mybb · mybb13 авг. 2025 г.
- CVE-2011-513341В плане
Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mybb · mybb30 авг. 2012 г.
- CVE-2016-940340В плане
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impac
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mybb · merge system31 янв. 2017 г.
- CVE-2016-942040В плане
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors rel
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mybb · merge system31 янв. 2017 г.
- CVE-2016-941240В плане
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mybb · merge system31 янв. 2017 г.
- CVE-2016-940240В плане
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mybb · merge system31 янв. 2017 г.
- CVE-2016-941640В плане
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows r
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mybb · merge system31 янв. 2017 г.
- CVE-2015-278640В плане
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %mybb · mybb29 мар. 2015 г.
- CVE-2006-021840В плане
Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %mybb · mybb16 янв. 2006 г.
- CVE-2018-1439239Наблюдать
The New Threads plugin before 1.2 for MyBB has XSS.
СредняяCVSS 6,1Proof of conceptEPSS 49 %mybb · new threads18 июл. 2018 г.
- CVE-2020-2261239Наблюдать
Installer RCE on settings file write in MyBB before 1.8.22.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mybb · mybb1 сент. 2023 г.
- CVE-2021-2789038Наблюдать
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
ВысокаяCVSS 8,8Proof of conceptEPSS 11 %mybb · mybb15 мар. 2021 г.
- CVE-2021-2794636Наблюдать
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %mybb · mybb15 мар. 2021 г.
- CVE-2018-1457536Наблюдать
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subje
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %mybb · trash bin21 мар. 2019 г.
- CVE-2019-1283034Наблюдать
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mybb · mybb15 июн. 2019 г.
- CVE-2023-5397934Наблюдать
MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %mybb · mybb22 дек. 2025 г.
- CVE-2015-897333Наблюдать
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to
ВысокаяCVSS 8,3Эксплойта нетEPSS 2 %mybb · merge system31 янв. 2017 г.
- CVE-2010-509632Наблюдать
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %mybb · mybb13 авг. 2012 г.
- CVE-2014-924031Наблюдать
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mybb · mybb3 дек. 2014 г.
- CVE-2013-693631Наблюдать
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %mybb · ajax forum stat4 дек. 2013 г.
- CVE-2016-941431Наблюдать
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leverag
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mybb · merge system31 янв. 2017 г.