CVE-2014-1840
MyBB <1.6.12 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.
Scores
EPSS
0.0032
EPSS Percentile
54.6%
Details
CWE
CWE-79
Status
published
Products (14)
mybb/mybb
< 1.6.12
mybb/mybb
mybb/mybb
mybb/mybb
mybb/mybb
mybb/mybb
mybb/mybb
mybb/mybb
mybb/mybb
mybb/mybb
... and 4 more
Published
Mar 03, 2014
Tracked Since
Feb 18, 2026