Vulnerabilities > Mybb > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-24 CVE-2017-8104 Path Traversal vulnerability in Mybb
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
network
low complexity
mybb CWE-22
5.3
2017-04-24 CVE-2017-8103 Cross-site Scripting vulnerability in Mybb
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
network
low complexity
mybb CWE-79
6.1
2017-01-31 CVE-2016-9421 Cross-site Scripting vulnerability in Mybb Merge System and Mybb
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
mybb CWE-79
6.1
2017-01-31 CVE-2016-9419 Cross-site Scripting vulnerability in Mybb
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
mybb CWE-79
6.1
2017-01-31 CVE-2016-9413 Improper Access Control vulnerability in Mybb
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
network
low complexity
mybb CWE-284
6.5
2017-01-31 CVE-2016-9411 Information Exposure vulnerability in Mybb
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.
network
low complexity
mybb CWE-200
5.3
2017-01-31 CVE-2016-9409 Cross-site Scripting vulnerability in Mybb
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.
network
low complexity
mybb CWE-79
6.1
2017-01-31 CVE-2016-9408 Cross-site Scripting vulnerability in Mybb
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.
network
low complexity
mybb CWE-79
6.1
2017-01-31 CVE-2016-9407 Cross-site Scripting vulnerability in Mybb
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs.
network
low complexity
mybb CWE-79
6.1
2017-01-31 CVE-2016-9406 Cross-site Scripting vulnerability in Mybb
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
mybb CWE-79
6.1