Mybulletinboard is a narrowly focused web-based bulletin-board platform that, despite its single-product footprint, maintains substantial prominence in the vulnerability landscape and occupies a modestly represented exposure band. The recurring weakness classes affecting the product—SQL injection, cross-site scripting, and code injection—are characteristic of server-side web applications and reflect the input-validation and output-encoding demands of user-facing bulletin-board functionality. Public exploit code frequently becomes available for vulnerabilities in this product, making disclosed flaws attractive targets for automated scanning and weaponization. Defenders should treat this vendor's security advisories as significant for any deployment of Mybulletinboard and prioritize patching for internet-exposed instances. Current exploitation activity and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mybulletinboard over time
Signals from CVEs in this vendor scope (212 CVEs).
212 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24734HIGH MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, mak | Mar 9, 2022 | 7.2 | 82 | NO | YES |
CVE-2018-17128MEDIUM A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | Sep 17, 2018 | 5.4 | 70 | NO | YES |
CVE-2018-14392MEDIUM The New Threads plugin before 1.2 for MyBB has XSS. | Jul 19, 2018 | 6.1 | 56 | NO | YES |
CVE-2008-0382HIGH Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a result | Jan 22, 2008 | 7.5 | 51 | NO | YES |
CVE-2011-10018CRITICAL myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting paylo | Aug 13, 2025 | 9.8 | 44 | NO | YES |
CVE-2021-27890HIGH SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. | Mar 15, 2021 | 8.8 | 43 | NO | YES |
CVE-2017-16780CRITICAL The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. | Nov 10, 2017 | 9.8 | 43 | NO | YES |
CVE-2018-14575HIGH Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject. | Mar 21, 2019 | 8.8 | 39 | NO | YES |
CVE-2021-27946HIGH SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). | Mar 15, 2021 | 8.8 | 38 | NO | YES |
CVE-2010-5096HIGH Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_se | Aug 13, 2012 | 7.5 | 34 | NO | YES |
Signals from CVEs in this vendor scope (212 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mybulletinboard.
Media articles that mention a CVE ID that affects a product developed by Mybulletinboard — matched by CVE ID, not by vendor name.