CVE-2018-25132 PUBLISHED

MyBB Trending Widget Plugin 1.2 - Cross-Site Scripting

Assigner: VulnCheck
Reserved: 24.12.2025 Published: 23.01.2026 Updated: 23.01.2026

MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor zainali99
Product MyBB Trending Widget Plugin
Versions
  • Version 1.2 is affected

Credits

  • 0xB9 finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE