CVE-2016-9417: Mybb Merge System

High severity, CVSS 7.4. EPSS: 1.7% chance of exploitation in the next 30 days.

The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

Affected products

  • Mybb Merge System: up to and including 1.8.7
  • Mybb Mybb: up to and including 1.8.7

Published 2017-01-31. Last modified 2026-06-17.