CVE-2023-53979: Mybb

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.

Affected products

  • Mybb Mybb: version 1.8.32 only

Published 2025-12-22. Last modified 2026-06-17.