CVE-2019-12830: Mybb

High severity, CVSS 8.7. EPSS: 1% chance of exploitation in the next 30 days.

In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.

Affected products

  • Mybb Mybb: before 1.8.21 (fixed in 1.8.21)

Published 2019-06-15. Last modified 2026-06-17.