CVE-2018-25248

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb_downloads:2.0.3:*:*:*:*:mybb:*:*

History

No history.

Information

Published : 2026-04-04 14:16

Updated : 2026-07-20 20:10


NVD link : CVE-2018-25248

Mitre link : CVE-2018-25248

CVE.ORG link : CVE-2018-25248


JSON object : View

Products Affected

mybb

  • mybb_downloads
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')