mybb records
156 published records for vendor mybb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 1.3%
- Pre-auth RCE
- 20
- With a fix record
- 1.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-918 Server-Side Request Forgery (SSRF)6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
The weakness classes this vendor ships most often: where to look.
CWEAll records
156 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2022-24734Weaponized | Remote code execution in mybbmybb · mybb · CWE-94 | High7.2 | — | 77.8% | Mar 9, 2022 |
43Plan | CVE-2018-17128Proof of concept | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.mybb · mybb · CWE-79 | Medium5.4 | — | 74.8% | Sep 17, 2018 |
41Plan | CVE-2017-16780Proof of concept | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.mybb · mybb · CWE-352 | Critical9.8 | — | 5.8% | Nov 10, 2017 |
41Plan | CVE-2011-10018Weaponized | myBB 1.6.4 Backdoor Arbitrary Command Executionmybb · mybb · CWE-94 | Critical10.0 | — | 2.8% | Aug 13, 2025 |
41Plan | CVE-2015-8974No exploit | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x mybb · merge system · CWE-89 | Critical10.0 | — | 2.1% | Jan 31, 2017 |
41Plan | CVE-2011-5133No exploit | Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.mybb · mybb | Critical10.0 | — | 1.7% | Aug 30, 2012 |
40Plan | CVE-2016-9403No exploit | newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impacmybb · merge system · CWE-264 | Critical9.8 | — | 2.6% | Jan 31, 2017 |
40Plan | CVE-2016-9420No exploit | MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors relmybb · merge system · CWE-20 | Critical9.8 | — | 2.6% | Jan 31, 2017 |
40Plan | CVE-2016-9412No exploit | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related tomybb · merge system · CWE-284 | Critical9.8 | — | 2.2% | Jan 31, 2017 |
40Plan | CVE-2016-9402No exploit | SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allowmybb · merge system · CWE-89 | Critical9.8 | — | 2.1% | Jan 31, 2017 |
40Plan | CVE-2016-9416No exploit | SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows rmybb · merge system · CWE-89 | Critical9.8 | — | 2.1% | Jan 31, 2017 |
40Plan | CVE-2015-2786No exploit | Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notificationsmybb · mybb | Critical10.0 | — | 1.4% | Mar 29, 2015 |
40Plan | CVE-2006-0218No exploit | Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) adminmybb · mybb | Critical10.0 | — | 1.2% | Jan 16, 2006 |
39Monitor | CVE-2018-14392Proof of concept | The New Threads plugin before 1.2 for MyBB has XSS.mybb · new threads · CWE-79 | Medium6.1 | — | 48.6% | Jul 18, 2018 |
39Monitor | CVE-2020-22612No exploit | Installer RCE on settings file write in MyBB before 1.8.22.mybb · mybb · CWE-94 | Critical9.8 | — | 0.7% | Sep 1, 2023 |
38Monitor | CVE-2021-27890Proof of concept | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.mybb · mybb · CWE-89 | High8.8 | — | 10.7% | Mar 15, 2021 |
36Monitor | CVE-2021-27946Proof of concept | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.mybb · mybb · CWE-89 | High8.8 | — | 4.2% | Mar 15, 2021 |
36Monitor | CVE-2018-14575Proof of concept | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subjemybb · trash bin · CWE-79 | High8.8 | — | 2.4% | Mar 21, 2019 |
34Monitor | CVE-2019-12830No exploit | In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistentmybb · mybb · CWE-79 | High8.7 | — | 1.0% | Jun 15, 2019 |
34Monitor | CVE-2023-53979No exploit | MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilitiesmybb · mybb · CWE-22 | High8.6 | — | 0.8% | Dec 22, 2025 |
33Monitor | CVE-2015-8973No exploit | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers tomybb · merge system · CWE-284 | High8.3 | — | 1.6% | Jan 31, 2017 |
32Monitor | CVE-2010-5096Proof of concept | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands vmybb · mybb · CWE-89 | High7.5 | — | 5.6% | Aug 13, 2012 |
31Monitor | CVE-2014-9240Proof of concept | SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL mybb · mybb · CWE-89 | High7.5 | — | 3.5% | Dec 3, 2014 |
31Monitor | CVE-2013-6936Proof of concept | Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote mybb · ajax forum stat · CWE-89 | High7.5 | — | 2.5% | Dec 4, 2013 |
31Monitor | CVE-2016-9414No exploit | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveragmybb · merge system · CWE-200 | High7.5 | — | 2.3% | Jan 31, 2017 |
- CVE-2022-2473451Plan
Remote code execution in mybb
HighCVSS 7.2WeaponizedEPSS 78%mybb · mybbMar 9, 2022
- CVE-2018-1712843Plan
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
MediumCVSS 5.4Proof of conceptEPSS 75%mybb · mybbSep 17, 2018
- CVE-2017-1678041Plan
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
CriticalCVSS 9.8Proof of conceptEPSS 6%mybb · mybbNov 10, 2017
- CVE-2011-1001841Plan
myBB 1.6.4 Backdoor Arbitrary Command Execution
CriticalCVSS 10.0WeaponizedEPSS 3%mybb · mybbAug 13, 2025
- CVE-2015-897441Plan
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x
CriticalCVSS 10.0No exploitEPSS 2%mybb · merge systemJan 31, 2017
- CVE-2011-513341Plan
Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.
CriticalCVSS 10.0No exploitEPSS 2%mybb · mybbAug 30, 2012
- CVE-2016-940340Plan
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impac
CriticalCVSS 9.8No exploitEPSS 3%mybb · merge systemJan 31, 2017
- CVE-2016-942040Plan
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors rel
CriticalCVSS 9.8No exploitEPSS 3%mybb · merge systemJan 31, 2017
- CVE-2016-941240Plan
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to
CriticalCVSS 9.8No exploitEPSS 2%mybb · merge systemJan 31, 2017
- CVE-2016-940240Plan
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow
CriticalCVSS 9.8No exploitEPSS 2%mybb · merge systemJan 31, 2017
- CVE-2016-941640Plan
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows r
CriticalCVSS 9.8No exploitEPSS 2%mybb · merge systemJan 31, 2017
- CVE-2015-278640Plan
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications
CriticalCVSS 10.0No exploitEPSS 1%mybb · mybbMar 29, 2015
- CVE-2006-021840Plan
Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin
CriticalCVSS 10.0No exploitEPSS 1%mybb · mybbJan 16, 2006
- CVE-2018-1439239Monitor
The New Threads plugin before 1.2 for MyBB has XSS.
MediumCVSS 6.1Proof of conceptEPSS 49%mybb · new threadsJul 18, 2018
- CVE-2020-2261239Monitor
Installer RCE on settings file write in MyBB before 1.8.22.
CriticalCVSS 9.8No exploitEPSS 1%mybb · mybbSep 1, 2023
- CVE-2021-2789038Monitor
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
HighCVSS 8.8Proof of conceptEPSS 11%mybb · mybbMar 15, 2021
- CVE-2021-2794636Monitor
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.
HighCVSS 8.8Proof of conceptEPSS 4%mybb · mybbMar 15, 2021
- CVE-2018-1457536Monitor
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subje
HighCVSS 8.8Proof of conceptEPSS 2%mybb · trash binMar 21, 2019
- CVE-2019-1283034Monitor
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent
HighCVSS 8.7No exploitEPSS 1%mybb · mybbJun 15, 2019
- CVE-2023-5397934Monitor
MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities
HighCVSS 8.6No exploitEPSS 1%mybb · mybbDec 22, 2025
- CVE-2015-897333Monitor
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to
HighCVSS 8.3No exploitEPSS 2%mybb · merge systemJan 31, 2017
- CVE-2010-509632Monitor
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5Proof of conceptEPSS 6%mybb · mybbAug 13, 2012
- CVE-2014-924031Monitor
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL
HighCVSS 7.5Proof of conceptEPSS 3%mybb · mybbDec 3, 2014
- CVE-2013-693631Monitor
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote
HighCVSS 7.5Proof of conceptEPSS 2%mybb · ajax forum statDec 4, 2013
- CVE-2016-941431Monitor
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leverag
HighCVSS 7.5No exploitEPSS 2%mybb · merge systemJan 31, 2017