CVE-2019-12830: Mybb
High severity, CVSS 8.7. EPSS: 1% chance of exploitation in the next 30 days.
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.
Affected products
- Mybb Mybb: before 1.8.21 (fixed in 1.8.21)
Published 2019-06-15. Last modified 2026-06-17.