CVE-2018-25247

MEDIUM

MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles

Title source: cna
STIX 2.1

Description

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profile, where liked posts are displayed without sanitization.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/45179

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-45179
https://www.exploit-db.com/exploits/45179
Third Party Advisory third-party-advisory
VulnCheck Advisory: MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles
https://www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-user-profiles

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 7.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
MyBB/MyBB Like Plugin 3.0.0
mybb/thankyou\/like_system < 3.0.0
Published Apr 04, 2026
Tracked Since Apr 04, 2026