CVE-2018-25132

MEDIUM

MyBB Trending Widget Plugin 1.2 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25132. PoCs published by 0xB9.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the MyBB Trending Widget Plugin 1.2, where unsanitized thread titles allow arbitrary JavaScript execution when rendered in the widget.

Description

MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/49504

This exploit demonstrates a stored XSS vulnerability in the MyBB Trending Widget Plugin 1.2, where unsanitized thread titles allow arbitrary JavaScript execution when rendered in the widget.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MyBB Trending Widget Plugin 1.2
Auth required
Prerequisites: Access to create or modify a trending thread title · Trending Widget Plugin 1.2 installed on MyBB
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
mybb/trending_widget 1.2
Published Jan 23, 2026
Tracked Since Feb 18, 2026