PT-2026-77169 · Mybb · Mybb

CVE-2026-45115

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.40
Description The Buddy/Ignore component fails to sanitize usernames correctly, enabling JavaScript code injection via a specially crafted username. The issue occurs because the User CP Buddy/Ignore list and the Select Buddies list in Private Messages use the htmlspecialchars uni() function, which may leave single quotes unescaped. The injection is triggered when a user selects Yes during the confirmation process for removing a username in the 'usercp.php' endpoint, or when selecting a username via the onclick handler in the 'xmlhttp.php' Select Buddies popup.
Recommendations Update to version 1.8.40.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45115
GHSA-P766-QQXV-RFC2

Affected Products

Mybb