CVE-2018-10365

MEDIUM

Threads to Link plugin 1.3 - MyBB - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-10365. PoCs published by 0xB9.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in the MyBB Threads to Link Plugin v1.3. The attack involves injecting malicious JavaScript into the Thread Link field during thread editing, which executes when the thread is viewed.

Description

An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/44547

This exploit demonstrates a persistent XSS vulnerability in the MyBB Threads to Link Plugin v1.3. The attack involves injecting malicious JavaScript into the Thread Link field during thread editing, which executes when the thread is viewed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MyBB Threads to Link Plugin v1.3
Auth required
Prerequisites: Valid user account with permission to edit threads
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44547/

Scores

CVSS v3 5.4
EPSS 0.0158
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
threads_to_link_project/threads_to_link 1.3
Published May 01, 2018
Tracked Since Feb 18, 2026