Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 18 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims visit affected profiles. | |
| Title | MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF | |
| First Time appeared |
Mybb
Mybb mybb |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:mybb:mybb:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Mybb
Mybb mybb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-18T13:43:44.349Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47934
Updated: 2026-05-18T13:43:25.517Z
Status : Deferred
Published: 2026-05-16T16:16:21.267
Modified: 2026-06-17T04:18:47.163
Link: CVE-2021-47934
No data.
OpenCVE Enrichment
Updated: 2026-05-16T18:15:28Z