CVE-2026-45118Critical· 9.3▾ MidnightMyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redir…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the Click here if you don't want to wait any longer link because $force_redirect is true, allowing script execution when a victim selects the link. This issue is fixed in version 1.8.40.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45733High· 8.3Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases
CVE-2026-91127High· 8.2File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications
CVE-2026-62324Medium· 5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor
CVE-2026-58263High· 7.2Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
CVE-2026-8245Medium· 5.4Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href="" (<a href="{$linkURL}"…
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands