CVE-2018-11430

MEDIUM

Moderator Log Notes 1.1 - Stored Cross-Site Scripting in Mod Notes Textarea

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-11430. PoCs published by 0xB9.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the MyBB Moderator Log Notes Plugin 1.1. The payload is injected via the moderator notes textarea and executes when viewed in the modCP or ACP.

Description

An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/44754

This exploit demonstrates a stored XSS vulnerability in the MyBB Moderator Log Notes Plugin 1.1. The payload is injected via the moderator notes textarea and executes when viewed in the modCP or ACP.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MyBB Moderator Log Notes Plugin 1.1
Auth required
Prerequisites: Access to moderator or admin panel · MyBB Moderator Log Notes Plugin 1.1 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44754/

Scores

CVSS v3 5.4
EPSS 0.0059
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
moderator_log_notes_project/moderator_log_notes 1.1
Published May 28, 2018
Tracked Since Feb 18, 2026