MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.
References
| Link | Resource |
|---|---|
| https://github.com/zainali99/trends-widget | Product |
| https://www.exploit-db.com/exploits/49504 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/mybb-trending-widget-plugin-cross-site-scripting | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-23 17:15
Updated : 2026-06-17 01:54
NVD link : CVE-2018-25132
Mitre link : CVE-2018-25132
CVE.ORG link : CVE-2018-25132
JSON object : View
Products Affected
mybb
- trending_widget
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
