5.1
CVE-2018-25132 - MyBB Trending Widget Plugin 1.2 - Cross-Site Scripting
MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.
5.1
CVE-2018-25116 - MyBB Thread Redirect Plugin 0.2.1 - Cross-Site Scripting
MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.
5.1
CVE-2025-71177 - LavaLite CMS <= 10.1.0 Stored XSS via Package Creation and Search
LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without properβ¦
6
CVE-2026-1299 - email BytesGenerator header injection due to unquoted newlines
The email module, specifically the "BytesGenerator" class, didnβt properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email foldiβ¦
0.0
CVE-2026-24647 -
Not used
0.0
CVE-2026-24646 -
Not used
0.0
CVE-2026-24648 -
Not used
0.0
CVE-2026-24649 -
Not used
0.0
CVE-2026-24642 -
Not used
0.0
CVE-2026-24643 -
Not used