📦 Mybb

by Mybb

🔍 What is Mybb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2011-10018

CRITICAL CVSS 9.8 Aug 13, 2025

CVE-2011-10018 is a critical backdoor vulnerability in myBB 1.6.4 that allows unauthenticated remote attackers to execute arbitrary PHP code via manipulated cookies. This results in complete compromis...

CVE-2023-53979

HIGH CVSS 8.8 Dec 22, 2025

This vulnerability allows authenticated administrators in MyBB 1.8.32 to bypass avatar upload restrictions and execute arbitrary code through a chained attack. Attackers can modify upload paths, uploa...

CVE-2025-48940

HIGH CVSS 7.2 Jun 2, 2025

This vulnerability in MyBB forum software allows attackers to perform local file inclusion (LFI) through improper input validation in the upgrade component. Attackers can read arbitrary files from the...

CVE-2025-29457

HIGH CVSS 7.6 Apr 17, 2025

This vulnerability in MyBB 1.8.38 allows remote attackers to obtain sensitive information through the Import a Theme function, potentially via Server-Side Request Forgery (SSRF). The vulnerability aff...

CVE-2025-29459

HIGH CVSS 7.6 Apr 17, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MyBB 1.8.38's Mail function that could allow attackers to access internal network resources. The vulnerability affects MyBB for...

CVE-2023-46251

HIGH CVSS 7.5 Nov 6, 2023

This DOM-based XSS vulnerability in MyBB forum software allows attackers to execute malicious JavaScript in victims' browsers by tricking them into viewing specially crafted MyCode messages in the vis...

CVE-2022-24734

HIGH CVSS 7.2 Mar 9, 2022

This vulnerability allows authenticated administrators with settings management permissions to inject PHP code into MyBB forum settings, leading to remote code execution. It affects MyBB versions befo...

CVE-2021-43281

HIGH CVSS 7.2 Nov 4, 2021

This vulnerability allows authenticated MyBB administrators with 'Can manage settings?' permission to inject and execute arbitrary PHP code through the Admin Control Panel's Settings management module...

CVE-2021-27890

HIGH CVSS 8.8 Mar 15, 2021

CVE-2021-27890 is a SQL injection vulnerability in MyBB forum software that allows attackers to execute arbitrary SQL commands via malicious theme XML files. This can lead to remote code execution by ...

CVE-2021-27947

HIGH CVSS 7.2 Mar 15, 2021

This SQL injection vulnerability in MyBB allows attackers to execute arbitrary SQL commands through the Copy Forum feature in Forum Management. It affects MyBB installations before version 1.8.26 wher...

CVE-2023-53976

MEDIUM CVSS 5.4 Dec 22, 2025

This stored XSS vulnerability in myBB Forums allows authenticated administrators to inject malicious JavaScript into template titles. When these templates are viewed, the scripts execute in users' bro...

CVE-2023-53977

MEDIUM CVSS 5.4 Dec 22, 2025

This stored XSS vulnerability in myBB Forums allows authenticated administrators to inject malicious JavaScript when creating new forums. The injected scripts execute when other users view the forum l...

CVE-2023-53978

MEDIUM CVSS 5.4 Dec 22, 2025

CVE-2023-53978 is a stored cross-site scripting vulnerability in myBB Forums that allows authenticated administrators to inject malicious JavaScript when creating forum announcements. This vulnerabili...

CVE-2024-52702

MEDIUM CVSS 5.4 Nov 20, 2024

A stored cross-site scripting (XSS) vulnerability in MyBB v1.8.38 allows attackers to inject malicious scripts into the Website Name parameter during installation. This could enable session hijacking,...

CVE-2024-23336

MEDIUM CVSS 5.0 May 1, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MyBB forum software where the default disallowed remote hosts list doesn't include the complete 127.0.0.0/8 block, allowing att...