Mybb
This hub aggregates every CVE we track for Mybb, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
158
CVEs tracked
14
Critical
45
High
0
In CISA KEV
Severity distribution
MEDIUM94HIGH45CRITICAL14LOW5
Monthly trend
0
0
1
0
0
0
0
4
0
2
0
1
0
0
0
4
0
0
0
0
0
0
0
18
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mybb.
- CVE-2026-45118MyBB: Contact page reflected XSS9.3
- CVE-2026-45117MyBB: Installer database configuration RCE9.8
- CVE-2026-45129MyBB: ACP Recovery Codes CSRF4.6
- CVE-2026-45124MyBB: Mod CP report resolution missing authorization4.3
- CVE-2026-45120MyBB: Insufficient authorization for private calendar events5.4
- CVE-2026-47245MyBB: Buddy list corruption4.3
- CVE-2026-45734MyBB: Default CAPTCHA missing invalidation5.3
- CVE-2026-45125MyBB: Email User CRLF injection5.3
- CVE-2026-45122MyBB: Insufficient permission check for calendar event move4.3
- CVE-2026-45119MyBB: ACP UTF-8 Conversion CSRF4.6
- CVE-2026-45126MyBB: ACP Questions state CSRF3.5
- CVE-2026-45116MyBB: Profile field type confusion XSS8.7
- CVE-2026-45115MyBB: Buddy/ignore list username XSS8.7
- CVE-2026-45121MyBB: Insufficient permission check for calendar select4.3
- CVE-2026-46482MyBB: Security Question insufficient validation5.3
Product normalization is registry-driven with AI assist and human review. How it works