Remote Information Disclosure in MyBB by MyBB Group
CVE-2025-29458
7.6HIGH
What is CVE-2025-29458?
MyBB version 1.8.38 contains a vulnerability in the Change Avatar functionality, where a remote attacker can exploit this flaw to gain unauthorized access to sensitive user information. This issue elevates the risk profile for users, making it crucial for administrators to patch and secure their MyBB installations immediately.