4
I Use This!
Inactive
Analyzed about 20 hours ago. based on code collected about 21 hours ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2025-48941 BDSA-2025-4889 Jun 02, 2025 MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attack more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2025-48940 BDSA-2025-4888 Jun 02, 2025 MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attacke more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2024-23336 BDSA-2024-2148 May 01, 2024 MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result i more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2024-23335 BDSA-2024-2145 May 01, 2024 MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2023-46251 Medium Nov 06, 2023 MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2023-45556 Medium Nov 06, 2023 Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the t more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2023-41362 High Aug 29, 2023 MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some valida more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2023-28467 BDSA-2023-1246 Medium May 22, 2023 In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2022-45867 BDSA-2023-0002 High Jan 03, 2023 MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14
CVE-2022-43709 BDSA-2022-3326 Medium Nov 22, 2022 MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct us more...
1.8.26, 1.8.22, 1.8.21, 1.8.20, 1.8.19, 1.8.18, 1.8.17, 1.8.16, 1.8.15, 1.8.14