CVE-2021-47905

MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicious scripts that will execute in the admin interface when viewing delete account reasons.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:delete_account:1.4:*:*:*:*:mybb:*:*

History

09 Apr 2026, 13:53

Type Values Removed Values Added
First Time Mybb
Mybb delete Account
CPE cpe:2.3:a:mybb:delete_account:1.4:*:*:*:*:mybb:*:*
Summary
  • (es) MyBB Delete Account Plugin 1.4 contiene una vulnerabilidad de cross-site scripting en el campo de entrada de la razón de eliminación de cuenta. Los atacantes pueden inyectar scripts maliciosos que se ejecutarán en la interfaz de administración al ver las razones de eliminación de cuenta.
References () https://github.com/vintagedaddyo/MyBB_Plugin-Delete_Account/ - () https://github.com/vintagedaddyo/MyBB_Plugin-Delete_Account/ - Product
References () https://www.exploit-db.com/exploits/49500 - () https://www.exploit-db.com/exploits/49500 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/mybb-delete-account-plugin-cross-site-scripting - () https://www.vulncheck.com/advisories/mybb-delete-account-plugin-cross-site-scripting - Third Party Advisory

23 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49500 - () https://www.exploit-db.com/exploits/49500 -

23 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 17:16

Updated : 2026-04-09 13:53


NVD link : CVE-2021-47905

Mitre link : CVE-2021-47905

CVE.ORG link : CVE-2021-47905


JSON object : View

Products Affected

mybb

  • delete_account
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')