CVE-2023-27890: Export User Project Export User

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected products

Published 2023-04-14. Last modified 2026-06-17.