CVE-2023-53978

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the announcement title field when adding announcements through the 'Forums and Posts' > 'Forum Announcements' interface, causing arbitrary JavaScript to execute when the announcement is displayed on the forum.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb:1.8.26:*:*:*:*:*:*:*

History

27 Dec 2025, 17:15

Type Values Removed Values Added
References () https://www.vulncheck.com/advisories/mybb-forums-stored-cross-site-scripting-via-forum-announcements - Third Party Advisory, Exploit () https://www.vulncheck.com/advisories/mybb-forums-stored-cross-site-scripting-via-forum-announcements - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 5.4

26 Dec 2025, 16:06

Type Values Removed Values Added
First Time Mybb
Mybb mybb
References () https://mybb.com/ - () https://mybb.com/ - Product
References () https://www.exploit-db.com/exploits/51136 - () https://www.exploit-db.com/exploits/51136 - Exploit
References () https://www.vulncheck.com/advisories/mybb-forums-stored-cross-site-scripting-via-forum-announcements - () https://www.vulncheck.com/advisories/mybb-forums-stored-cross-site-scripting-via-forum-announcements - Third Party Advisory, Exploit
CPE cpe:2.3:a:mybb:mybb:1.8.26:*:*:*:*:*:*:*

22 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-22 22:16

Updated : 2025-12-27 17:15


NVD link : CVE-2023-53978

Mitre link : CVE-2023-53978

CVE.ORG link : CVE-2023-53978


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')