mybb has 3 CVEs on record. The busiest recent month was April 2026 with 3. The median CVSS is 6.4 (medium). The most common weakness class is CWE-79 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Weakness classes
Products
- my_arcade 1
- mybb_downloads 1
- thankyou/like_system 1
Worst active — by depth score
CVE-2018-25248High· 7.2MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field40CVE-2018-25249Medium· 6.4MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments35CVE-2018-25247Medium· 6.1MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability34
mybb vulnerabilities
CVEs affecting mybb, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2018-25249Medium· 6.4MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments
MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in …
CVE-2018-25248High· 7.2MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field
MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code …
CVE-2018-25247Medium· 6.1MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability
MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the u…