mybb kayıtları
mybb üreticisine ait 156 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %1,3
- Pre-auth RCE
- 20
- Düzeltme kaydı olan
- %1,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-918 Server-Side Request Forgery (SSRF)6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
156 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2022-24734Silahlaştırılmış | Remote code execution in mybbmybb · mybb · CWE-94 | Yüksek7,2 | — | %77,8 | 9 Mar 2022 |
43Planlayın | CVE-2018-17128Kavram kanıtı | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.mybb · mybb · CWE-79 | Orta5,4 | — | %74,8 | 17 Eyl 2018 |
41Planlayın | CVE-2017-16780Kavram kanıtı | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.mybb · mybb · CWE-352 | Kritik9,8 | — | %5,8 | 10 Kas 2017 |
41Planlayın | CVE-2015-8974İstismar yok | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x mybb · merge system · CWE-89 | Kritik10,0 | — | %2,1 | 31 Oca 2017 |
41Planlayın | CVE-2011-10018Silahlaştırılmış | myBB 1.6.4 Backdoor Arbitrary Command Executionmybb · mybb · CWE-94 | Kritik10,0 | — | %2,0 | 13 Ağu 2025 |
41Planlayın | CVE-2011-5133İstismar yok | Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.mybb · mybb | Kritik10,0 | — | %1,7 | 30 Ağu 2012 |
40Planlayın | CVE-2016-9403İstismar yok | newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impacmybb · merge system · CWE-264 | Kritik9,8 | — | %2,6 | 31 Oca 2017 |
40Planlayın | CVE-2016-9420İstismar yok | MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors relmybb · merge system · CWE-20 | Kritik9,8 | — | %2,6 | 31 Oca 2017 |
40Planlayın | CVE-2016-9412İstismar yok | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related tomybb · merge system · CWE-284 | Kritik9,8 | — | %2,2 | 31 Oca 2017 |
40Planlayın | CVE-2016-9402İstismar yok | SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allowmybb · merge system · CWE-89 | Kritik9,8 | — | %2,1 | 31 Oca 2017 |
40Planlayın | CVE-2016-9416İstismar yok | SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows rmybb · merge system · CWE-89 | Kritik9,8 | — | %2,1 | 31 Oca 2017 |
40Planlayın | CVE-2015-2786İstismar yok | Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notificationsmybb · mybb | Kritik10,0 | — | %1,4 | 29 Mar 2015 |
40Planlayın | CVE-2006-0218İstismar yok | Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) adminmybb · mybb | Kritik10,0 | — | %1,2 | 16 Oca 2006 |
39İzleyin | CVE-2018-14392Kavram kanıtı | The New Threads plugin before 1.2 for MyBB has XSS.mybb · new threads · CWE-79 | Orta6,1 | — | %48,6 | 18 Tem 2018 |
39İzleyin | CVE-2020-22612İstismar yok | Installer RCE on settings file write in MyBB before 1.8.22.mybb · mybb · CWE-94 | Kritik9,8 | — | %0,7 | 1 Eyl 2023 |
38İzleyin | CVE-2021-27890Kavram kanıtı | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.mybb · mybb · CWE-89 | Yüksek8,8 | — | %10,6 | 15 Mar 2021 |
36İzleyin | CVE-2021-27946Kavram kanıtı | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.mybb · mybb · CWE-89 | Yüksek8,8 | — | %4,2 | 15 Mar 2021 |
36İzleyin | CVE-2018-14575Kavram kanıtı | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subjemybb · trash bin · CWE-79 | Yüksek8,8 | — | %2,4 | 21 Mar 2019 |
34İzleyin | CVE-2019-12830İstismar yok | In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistentmybb · mybb · CWE-79 | Yüksek8,7 | — | %1,0 | 15 Haz 2019 |
34İzleyin | CVE-2023-53979İstismar yok | MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilitiesmybb · mybb · CWE-22 | Yüksek8,6 | — | %0,8 | 22 Ara 2025 |
33İzleyin | CVE-2015-8973İstismar yok | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers tomybb · merge system · CWE-284 | Yüksek8,3 | — | %1,6 | 31 Oca 2017 |
32İzleyin | CVE-2010-5096Kavram kanıtı | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands vmybb · mybb · CWE-89 | Yüksek7,5 | — | %5,6 | 13 Ağu 2012 |
31İzleyin | CVE-2014-9240Kavram kanıtı | SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL mybb · mybb · CWE-89 | Yüksek7,5 | — | %3,5 | 3 Ara 2014 |
31İzleyin | CVE-2013-6936Kavram kanıtı | Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote mybb · ajax forum stat · CWE-89 | Yüksek7,5 | — | %2,5 | 4 Ara 2013 |
31İzleyin | CVE-2016-9414İstismar yok | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveragmybb · merge system · CWE-200 | Yüksek7,5 | — | %2,3 | 31 Oca 2017 |
- CVE-2022-2473451Planlayın
Remote code execution in mybb
YüksekCVSS 7,2SilahlaştırılmışEPSS %78mybb · mybb9 Mar 2022
- CVE-2018-1712843Planlayın
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
OrtaCVSS 5,4Kavram kanıtıEPSS %75mybb · mybb17 Eyl 2018
- CVE-2017-1678041Planlayın
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
KritikCVSS 9,8Kavram kanıtıEPSS %6mybb · mybb10 Kas 2017
- CVE-2015-897441Planlayın
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x
KritikCVSS 10,0İstismar yokEPSS %2mybb · merge system31 Oca 2017
- CVE-2011-1001841Planlayın
myBB 1.6.4 Backdoor Arbitrary Command Execution
KritikCVSS 10,0SilahlaştırılmışEPSS %2mybb · mybb13 Ağu 2025
- CVE-2011-513341Planlayın
Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list.
KritikCVSS 10,0İstismar yokEPSS %2mybb · mybb30 Ağu 2012
- CVE-2016-940340Planlayın
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impac
KritikCVSS 9,8İstismar yokEPSS %3mybb · merge system31 Oca 2017
- CVE-2016-942040Planlayın
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors rel
KritikCVSS 9,8İstismar yokEPSS %3mybb · merge system31 Oca 2017
- CVE-2016-941240Planlayın
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to
KritikCVSS 9,8İstismar yokEPSS %2mybb · merge system31 Oca 2017
- CVE-2016-940240Planlayın
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow
KritikCVSS 9,8İstismar yokEPSS %2mybb · merge system31 Oca 2017
- CVE-2016-941640Planlayın
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows r
KritikCVSS 9,8İstismar yokEPSS %2mybb · merge system31 Oca 2017
- CVE-2015-278640Planlayın
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications
KritikCVSS 10,0İstismar yokEPSS %1mybb · mybb29 Mar 2015
- CVE-2006-021840Planlayın
Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin
KritikCVSS 10,0İstismar yokEPSS %1mybb · mybb16 Oca 2006
- CVE-2018-1439239İzleyin
The New Threads plugin before 1.2 for MyBB has XSS.
OrtaCVSS 6,1Kavram kanıtıEPSS %49mybb · new threads18 Tem 2018
- CVE-2020-2261239İzleyin
Installer RCE on settings file write in MyBB before 1.8.22.
KritikCVSS 9,8İstismar yokEPSS %1mybb · mybb1 Eyl 2023
- CVE-2021-2789038İzleyin
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
YüksekCVSS 8,8Kavram kanıtıEPSS %11mybb · mybb15 Mar 2021
- CVE-2021-2794636İzleyin
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.
YüksekCVSS 8,8Kavram kanıtıEPSS %4mybb · mybb15 Mar 2021
- CVE-2018-1457536İzleyin
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subje
YüksekCVSS 8,8Kavram kanıtıEPSS %2mybb · trash bin21 Mar 2019
- CVE-2019-1283034İzleyin
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent
YüksekCVSS 8,7İstismar yokEPSS %1mybb · mybb15 Haz 2019
- CVE-2023-5397934İzleyin
MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities
YüksekCVSS 8,6İstismar yokEPSS %1mybb · mybb22 Ara 2025
- CVE-2015-897333İzleyin
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to
YüksekCVSS 8,3İstismar yokEPSS %2mybb · merge system31 Oca 2017
- CVE-2010-509632İzleyin
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5Kavram kanıtıEPSS %6mybb · mybb13 Ağu 2012
- CVE-2014-924031İzleyin
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL
YüksekCVSS 7,5Kavram kanıtıEPSS %3mybb · mybb3 Ara 2014
- CVE-2013-693631İzleyin
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote
YüksekCVSS 7,5Kavram kanıtıEPSS %2mybb · ajax forum stat4 Ara 2013
- CVE-2016-941431İzleyin
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leverag
YüksekCVSS 7,5İstismar yokEPSS %2mybb · merge system31 Oca 2017