Cross-Site Scripting Vulnerability in MyBB Like Plugin by MyBB
CVE-2018-25247
Key Information:
- Vendor
Mybb
- Status
- Vendor
- CVE Published:
- 4 April 2026
Badges
What is CVE-2018-25247?
The MyBB Like Plugin version 3.0.0 contains a vulnerability that permits cross-site scripting (XSS) attacks. This issue arises from the lack of proper validation and sanitization of user input in post subjects. Attackers can exploit this vulnerability by crafting posts or threads with malicious script tags in their subject lines. When other users visit the attacker's profile, the liked posts are displayed, causing the scripts to execute in the context of their browsers, potentially leading to unauthorized actions on behalf of the user. Implementing proper input validation and output sanitization is crucial to mitigate this risk.
Affected Version(s)
MyBB Like Plugin 3.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
