MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing the index page.
References
| Link | Resource |
|---|---|
| https://community.mybb.com/mods.php?action=view&pid=191 | Product |
| https://www.exploit-db.com/exploits/44420 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/mybb-recent-threads-persistent-cross-site-scripting | Third Party Advisory |
Configurations
History
01 May 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.mybb.com/mods.php?action=view&pid=191 - Product | |
| References | () https://www.exploit-db.com/exploits/44420 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/mybb-recent-threads-persistent-cross-site-scripting - Third Party Advisory | |
| First Time |
Dragonexpert recent Threads On Index
Dragonexpert |
|
| CPE | cpe:2.3:a:dragonexpert:recent_threads_on_index:17.0:*:*:*:*:mybb:*:* |
30 Apr 2026, 15:48
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-29 20:16
Updated : 2026-05-01 19:15
NVD link : CVE-2018-25309
Mitre link : CVE-2018-25309
CVE.ORG link : CVE-2018-25309
JSON object : View
Products Affected
dragonexpert
- recent_threads_on_index
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
