CVE-2018-6506: Minibb
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attribute of an SVG element in the supertitle field.
Affected products
- Minibb Minibb: version 3.2.2 only
Published 2018-02-12. Last modified 2026-06-17.