CVE-2018-25248

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb_downloads:2.0.3:*:*:*:*:mybb:*:*

History

10 Apr 2026, 21:21

Type Values Removed Values Added
First Time Mybb
Mybb mybb Downloads
CPE cpe:2.3:a:mybb:mybb_downloads:2.0.3:*:*:*:*:mybb:*:*
References () https://community.mybb.com/mods.php?action=view&pid=854 - () https://community.mybb.com/mods.php?action=view&pid=854 - Permissions Required, Product
References () https://www.exploit-db.com/exploits/44400 - () https://www.exploit-db.com/exploits/44400 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/mybb-downloads-plugin-persistent-xss-via-downloads-php - () https://www.vulncheck.com/advisories/mybb-downloads-plugin-persistent-xss-via-downloads-php - Third Party Advisory

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-04-10 21:21


NVD link : CVE-2018-25248

Mitre link : CVE-2018-25248

CVE.ORG link : CVE-2018-25248


JSON object : View

Products Affected

mybb

  • mybb_downloads
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')