Mybb
158 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mybb, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Mybb CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 4 |
| 2025-05 | 0 |
| 2025-06 | 2 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 4 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 18 |
| 2026-09 | 0 |
Severity
How the 158 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical14
- High45
- Medium94
- Low5
Latest CVEs
The 15 most recently published vulnerabilities affecting Mybb.
- CVE-2026-45118MyBB: Contact page reflected XSS9.3
- CVE-2026-45117MyBB: Installer database configuration RCE9.8
- CVE-2026-45129MyBB: ACP Recovery Codes CSRF4.6
- CVE-2026-45124MyBB: Mod CP report resolution missing authorization4.3
- CVE-2026-45120MyBB: Insufficient authorization for private calendar events5.4
- CVE-2026-47245MyBB: Buddy list corruption4.3
- CVE-2026-45734MyBB: Default CAPTCHA missing invalidation5.3
- CVE-2026-45125MyBB: Email User CRLF injection5.3
- CVE-2026-45122MyBB: Insufficient permission check for calendar event move4.3
- CVE-2026-45119MyBB: ACP UTF-8 Conversion CSRF4.6
- CVE-2026-45126MyBB: ACP Questions state CSRF3.5
- CVE-2026-45116MyBB: Profile field type confusion XSS8.7
- CVE-2026-45115MyBB: Buddy/ignore list username XSS8.7
- CVE-2026-45121MyBB: Insufficient permission check for calendar select4.3
- CVE-2026-46482MyBB: Security Question insufficient validation5.3
Product grouping is registry-driven, with AI assist and human review. How it works