MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing the index page.
Metrics
Affected Vendors & Products
References
History
Fri, 01 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dragonexpert
Dragonexpert recent Threads On Index |
|
| CPEs | cpe:2.3:a:dragonexpert:recent_threads_on_index:17.0:*:*:*:*:mybb:*:* | |
| Vendors & Products |
Dragonexpert
Dragonexpert recent Threads On Index |
Thu, 30 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing the index page. | |
| Title | MyBB Recent threads 17.0 Persistent Cross-Site Scripting | |
| First Time appeared |
Mybb
Mybb mybb |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:mybb:mybb:17.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Mybb
Mybb mybb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-29T19:24:39.993Z
Updated: 2026-04-30T13:07:56.870Z
Reserved: 2026-04-29T12:18:35.172Z
Link: CVE-2018-25309
Updated: 2026-04-30T13:07:53.387Z
Status : Analyzed
Published: 2026-04-29T20:16:26.463
Modified: 2026-05-01T19:15:42.213
Link: CVE-2018-25309
No data.