CVE detail
CVE-2018-25309 — CVE-2018-25309
Published 2026-04-29 · Modified 2026-06-17 · Vendor dragonexpert · Product recent_threads_on_index · Source nvd
HIGH
severity
CVSS-derived band
0.0026
EPSS probability
exploitation probability, 30d
18.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing the index page.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References