CVE-2018-19201: Mybb

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.

Affected products

  • Mybb Mybb: before 1.8.20 (fixed in 1.8.20)

Published 2019-03-29. Last modified 2026-06-17.