CVE-2018-25309

· NIST NVD ↗

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing the index page.

HIGH
CVSS severity
7.2
CVSS base score
2026-04-29
Published

CWE codes

CWE-79

Affected products

dragonexpert:recent_threads_on_index

Sources