CVE-2018-10580

MEDIUM

MyBB Latest Posts on Profile 1.1 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-10580. PoCs published by 0xB9.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in the MyBB Latest Posts on Profile Plugin v1.1. The PoC involves creating a thread with a malicious script in the subject, which executes when viewing the user's profile.

Description

The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/44608

This exploit demonstrates a persistent XSS vulnerability in the MyBB Latest Posts on Profile Plugin v1.1. The PoC involves creating a thread with a malicious script in the subject, which executes when viewing the user's profile.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MyBB Latest Posts on Profile Plugin v1.1
Auth required
Prerequisites: User account with permission to create threads
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44608/

Scores

CVSS v3 5.4
EPSS 0.0164
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
latest_posts_on_profile_project/latest_posts_on_profile 1.1
Published May 11, 2018
Tracked Since Feb 18, 2026