Skip to content
Noroxi

mybb records

156 published records for vendor mybb.

All records

156 records
  • Remote code execution in mybb

    HighCVSS 7.2WeaponizedEPSS 78%

    mybb · mybbMar 9, 2022

  • A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.

    MediumCVSS 5.4Proof of conceptEPSS 75%

    mybb · mybbSep 17, 2018

  • The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    mybb · mybbNov 10, 2017

  • myBB 1.6.4 Backdoor Arbitrary Command Execution

    CriticalCVSS 10.0WeaponizedEPSS 3%

    mybb · mybbAug 13, 2025

  • SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x

    CriticalCVSS 10.0No exploitEPSS 2%

    mybb · merge systemJan 31, 2017

  • Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.

    CriticalCVSS 10.0No exploitEPSS 2%

    mybb · mybbAug 30, 2012

  • newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impac

    CriticalCVSS 9.8No exploitEPSS 3%

    mybb · merge systemJan 31, 2017

  • MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors rel

    CriticalCVSS 9.8No exploitEPSS 3%

    mybb · merge systemJan 31, 2017

  • MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to

    CriticalCVSS 9.8No exploitEPSS 2%

    mybb · merge systemJan 31, 2017

  • SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow

    CriticalCVSS 9.8No exploitEPSS 2%

    mybb · merge systemJan 31, 2017

  • SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows r

    CriticalCVSS 9.8No exploitEPSS 2%

    mybb · merge systemJan 31, 2017

  • Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications

    CriticalCVSS 10.0No exploitEPSS 1%

    mybb · mybbMar 29, 2015

  • Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin

    CriticalCVSS 10.0No exploitEPSS 1%

    mybb · mybbJan 16, 2006

  • The New Threads plugin before 1.2 for MyBB has XSS.

    MediumCVSS 6.1Proof of conceptEPSS 49%

    mybb · new threadsJul 18, 2018

  • Installer RCE on settings file write in MyBB before 1.8.22.

    CriticalCVSS 9.8No exploitEPSS 1%

    mybb · mybbSep 1, 2023

  • SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.

    HighCVSS 8.8Proof of conceptEPSS 11%

    mybb · mybbMar 15, 2021

  • SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.

    HighCVSS 8.8Proof of conceptEPSS 4%

    mybb · mybbMar 15, 2021

  • Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subje

    HighCVSS 8.8Proof of conceptEPSS 2%

    mybb · trash binMar 21, 2019

  • In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent

    HighCVSS 8.7No exploitEPSS 1%

    mybb · mybbJun 15, 2019

  • MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities

    HighCVSS 8.6No exploitEPSS 1%

    mybb · mybbDec 22, 2025

  • CVE-2015-8973
    33Monitor

    xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to

    HighCVSS 8.3No exploitEPSS 2%

    mybb · merge systemJan 31, 2017

  • CVE-2010-5096
    32Monitor

    Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands v

    HighCVSS 7.5Proof of conceptEPSS 6%

    mybb · mybbAug 13, 2012

  • CVE-2014-9240
    31Monitor

    SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL

    HighCVSS 7.5Proof of conceptEPSS 3%

    mybb · mybbDec 3, 2014

  • CVE-2013-6936
    31Monitor

    Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote

    HighCVSS 7.5Proof of conceptEPSS 2%

    mybb · ajax forum statDec 4, 2013

  • CVE-2016-9414
    31Monitor

    MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leverag

    HighCVSS 7.5No exploitEPSS 2%

    mybb · merge systemJan 31, 2017