---
id: CVE-2018-25249
title: >-
  MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting
  vulnerability that allows authenticated users to inject malicious scripts
  through arcade game score comments
summary: >-
  MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting
  vulnerability that allows authenticated users to inject malicious scripts
  through arcade game score comments. Attackers can add crafted HTML and
  JavaScript payloads in …
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: mybb
product: my_arcade
affected:
  - my_arcade = 1.3
published: '2026-04-04'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25249'
references:
  - url: 'https://community.mybb.com/mods.php?action=view&pid=411'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/44186'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mybb-my-arcade-plugin-persistent-xss-via-comment
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00254
epssPercentile: 0.17315
ingestedAt: '2026-07-21T16:51:41.638Z'
---

## Overview

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit the comment.

## Affected

- `my_arcade = 1.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
