CVE-2018-11430
MEDIUMModerator Log Notes 1.1 - Stored Cross-Site Scripting in Mod Notes Textarea
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-11430. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the MyBB Moderator Log Notes Plugin 1.1. The payload is injected via the moderator notes textarea and executes when viewed in the modCP or ACP.
Description
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
Exploits (1)
exploitdb
WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/44754
This exploit demonstrates a stored XSS vulnerability in the MyBB Moderator Log Notes Plugin 1.1. The payload is injected via the moderator notes textarea and executes when viewed in the modCP or ACP.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
MyBB Moderator Log Notes Plugin 1.1
Auth required
Prerequisites:
Access to moderator or admin panel · MyBB Moderator Log Notes Plugin 1.1 installed
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/44754/
Scores
CVSS v3
5.4
EPSS
0.0059
EPSS Percentile
43.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
moderator_log_notes_project/moderator_log_notes
1.1
Published
May 28, 2018
Tracked Since
Feb 18, 2026