PT-2026-77169 · Mybb · Mybb
CVE-2026-45115
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB versions prior to 1.8.40
Description
The Buddy/Ignore component fails to sanitize usernames correctly, enabling JavaScript code injection via a specially crafted username. The issue occurs because the User CP Buddy/Ignore list and the Select Buddies list in Private Messages use the
htmlspecialchars uni() function, which may leave single quotes unescaped. The injection is triggered when a user selects Yes during the confirmation process for removing a username in the 'usercp.php' endpoint, or when selecting a username via the onclick handler in the 'xmlhttp.php' Select Buddies popup.Recommendations
Update to version 1.8.40.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb