Cross-Site Scripting and CSRF Vulnerabilities in MyBB Timeline Plugin by MyBB
CVE-2021-47934
Key Information:
- Vendor
Mybb
- Status
- Vendor
- CVE Published:
- 16 May 2026
Badges
What is CVE-2021-47934?
The MyBB Timeline Plugin version 1.0 is susceptible to cross-site scripting (XSS) vulnerabilities, which permit attackers to inject harmful scripts via thread titles, post content, and profile fields such as Location and Bio. Additionally, a cross-site request forgery (CSRF) vulnerability allows malicious actors to alter a user's cover picture through the timeline.php profile action by crafting deceptive forms that execute when victims access compromised profiles. This exposure can lead to unauthorized actions performed on behalf of users, compromising account safety and data integrity.
Affected Version(s)
MyBB Timeline Plugin 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
