Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MyBB — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in MyBB, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on security weaknesses affecting MyBB, a free open-source bulletin board software platform. It primarily catalogs known flaws such as cross-site scripting, SQL injection, and privilege escalation issues identified in various releases of the application. The collection spans historical data from the early days of the platform through recent security advisories published in the last decade, providing a comprehensive timeline of disclosed risks. By reviewing this index, users can track the vendor's response to reported bugs over time, analyze the frequency and severity of specific weakness classes like code injection or broken access control, and assess the overall vulnerability history of the product. This resource supports security researchers and administrators in understanding recurring patterns in MyBB's security posture and evaluating the potential impact of unpatched versions in their environments. The data is organized to facilitate quick lookup of past incidents without requiring access to fragmented vendor announcements or scattered technical reports.

Vendor: MyBB

CVE ID Title CVSS Severity Published
CVE-2026-45118 MyBB: Contact page reflected XSS CWE-83 9.3 Critical 2026-08-18
CVE-2026-45117 MyBB: Installer database configuration RCE CWE-94 9.8 Critical 2026-08-18
CVE-2026-45129 MyBB: ACP Recovery Codes CSRF CWE-352 4.6 Medium 2026-08-18
CVE-2026-45124 MyBB: Mod CP report resolution missing authorization CWE-862 4.3 Medium 2026-08-18
CVE-2026-45120 MyBB: Insufficient authorization for private calendar events CWE-639 5.4 Medium 2026-08-18
CVE-2026-47245 MyBB: Buddy list corruption CWE-252 4.3 Medium 2026-08-18
CVE-2026-45734 MyBB: Default CAPTCHA missing invalidation CWE-837 5.3 Medium 2026-08-18
CVE-2026-45125 MyBB: Email User CRLF injection CWE-93 5.3 Medium 2026-08-18
CVE-2026-45122 MyBB: Insufficient permission check for calendar event move CWE-863 4.3 Medium 2026-08-18
CVE-2026-45119 MyBB: ACP UTF-8 Conversion CSRF CWE-352 4.6 Medium 2026-08-18
CVE-2026-45126 MyBB: ACP Questions state CSRF CWE-352 3.5 Low 2026-08-18
CVE-2026-45116 MyBB: Profile field type confusion XSS CWE-79 8.7 High 2026-08-18
CVE-2026-45115 MyBB: Buddy/ignore list username XSS CWE-79 8.7 High 2026-08-18
CVE-2026-45121 MyBB: Insufficient permission check for calendar select CWE-863 4.3 Medium 2026-08-18
CVE-2026-46482 MyBB: Security Question insufficient validation CWE-636 5.3 Medium 2026-08-18
CVE-2026-45123 MyBB: IPv6 SSRF CWE-918 4.3 Medium 2026-08-18
CVE-2026-45128 MyBB: ACP Users View Manager default CSRF CWE-352 3.5 Low 2026-08-18
CVE-2026-45127 MyBB: ACP Mass Mail draft resend CSRF CWE-352 3.5 Low 2026-08-18
CVE-2023-53979 MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities CWE-22 8.8 High 2025-12-22
CVE-2025-48941 MyBB may disclosure unviewable threads' titles in searches CWE-1230 5.3 Medium 2025-06-02
CVE-2025-48940 MyBB's upgrade component vulnerable to local file inclusion CWE-22 7.2 High 2025-06-02
CVE-2024-23335 Backups directory .htaccess deletion in. MyBB CWE-20 4.7 Medium 2024-05-01
CVE-2024-23336 Incomplete disallowed remote addresses list in MyBB CWE-918 5.0 Medium 2024-05-01
CVE-2023-46251 Visual editor persistent Cross-site Scripting (XSS) in MyBB CWE-79 7.5 High 2023-11-06
CVE-2022-39265 Mail settings' command parameter injection in mybb CWE-74 7.2 High 2022-10-06
CVE-2022-24734 Remote code execution in mybb CWE-94 7.2 High 2022-03-09
CVE-2020-15139 XSS in MyBB CWE-79 8.8 High 2020-08-10

All 27 known CVE vulnerabilities affecting MyBB with full Chinese analysis, references, and POCs where available.