CVE-2018-25248: Mybb Downloads

High severity, CVSS 7.2. EPSS: 0.2% chance of exploitation in the next 30 days.

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php.

Affected products

  • Mybb Mybb Downloads: version 2.0.3 only

Published 2026-04-04. Last modified 2026-07-20.