CVE Tools

Mybulletinboard

57 CVEs tracked since 2005. Since Jun 2005, none of them reached CISA KEV.

Mybulletinboard CVEs per month

Jun 2005 to Jun 2009. Point at a month, or focus the strip and use the arrow keys.
Mybulletinboard CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0630
2005-07null or fewer
2005-0820
2005-0910
2005-1010
2005-1120
2005-12null or fewer
2006-0150
2006-0260
2006-0360
2006-0470
2006-0530
2006-0630
2006-0760
2006-0830
2006-0940
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-0430
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-0210
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-0610

Products

The products that kept showing up in Mybulletinboard's monthly top three, with their CVEs summed over those months.

  1. Mybulletinboard5717 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Mybulletinboard.

  1. CVE-2009-2230SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy param...7.5
  2. CVE-2008-0787SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private...6.5
  3. CVE-2008-0382Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in searc...7.5
  4. CVE-2007-2211SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.7.5
  5. CVE-2007-1964member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address ...6.0
  6. CVE-2007-1963SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Cli...7.5
  7. CVE-2006-4972Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary web script or HTML via the navbits[][name] param...5.1
  8. CVE-2006-4971MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the path in an error message.5.0
  9. CVE-2006-4706Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via a url BBCode tag that conta...6.8
  10. CVE-2006-4707Cross-site scripting (XSS) vulnerability in admin/global.php (aka the Admin CP login form) in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the...6.8
  11. CVE-2006-4449Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image...5.1
  12. CVE-2006-3954Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) ...5.0
  13. CVE-2006-3953Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.4.3
  14. CVE-2006-3775SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_...7.5
  15. CVE-2006-3759Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."5.0

The record

Peak rank
#9 in Jul 2006
Busiest month shown
Apr 2006, 7 CVEs
Months with a KEV entry
0 since Jun 2005
Monthly snapshots
17 since 2005
Mybulletinboard's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store