Home

Description

MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

PUBLISHED Reserved 2025-12-24 | Published 2026-01-23 | Updated 2026-01-23 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

1.2
affected

Credits

0xB9 finder

References

www.exploit-db.com/exploits/49504 (ExploitDB-49504) exploit

github.com/zainali99/trends-widget (Trending Widget GitHub Repository) product

www.vulncheck.com/...ding-widget-plugin-cross-site-scripting (VulnCheck Advisory: MyBB Trending Widget Plugin 1.2 - Cross-Site Scripting) third-party-advisory

cve.org (CVE-2018-25132)

nvd.nist.gov (CVE-2018-25132)

Download JSON