MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profile, where liked posts are displayed without sanitization.
References
| Link | Resource |
|---|---|
| https://community.mybb.com/mods.php?action=view&pid=360 | Product |
| https://www.exploit-db.com/exploits/45179 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-user-profiles | Third Party Advisory |
Configurations
History
20 Apr 2026, 14:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.mybb.com/mods.php?action=view&pid=360 - Product | |
| References | () https://www.exploit-db.com/exploits/45179 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-user-profiles - Third Party Advisory | |
| First Time |
Mybb thankyou\/like System
Mybb |
|
| CPE | cpe:2.3:a:mybb:thankyou\/like_system:*:*:*:*:*:mybb:*:* |
04 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-04 14:16
Updated : 2026-04-20 14:30
NVD link : CVE-2018-25247
Mitre link : CVE-2018-25247
CVE.ORG link : CVE-2018-25247
JSON object : View
Products Affected
mybb
- thankyou\/like_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
