MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.
References
| Link | Resource |
|---|---|
| https://github.com/zainali99/trends-widget | Product |
| https://www.exploit-db.com/exploits/49504 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/mybb-trending-widget-plugin-cross-site-scripting | Third Party Advisory |
Configurations
History
09 Apr 2026, 14:08
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/zainali99/trends-widget - Product | |
| References | () https://www.exploit-db.com/exploits/49504 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/mybb-trending-widget-plugin-cross-site-scripting - Third Party Advisory | |
| Summary |
|
|
| First Time |
Mybb
Mybb trending Widget |
|
| CPE | cpe:2.3:a:mybb:trending_widget:1.2:*:*:*:*:mybb:*:* |
23 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-23 17:15
Updated : 2026-04-09 14:08
NVD link : CVE-2018-25132
Mitre link : CVE-2018-25132
CVE.ORG link : CVE-2018-25132
JSON object : View
Products Affected
mybb
- trending_widget
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
