Security Advisory

CVE-2018-25247

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-04 13:51:12
Last updated 2026-05-25 23:40:59
Assigner VulnCheck
CVSS score 5.1
State PUBLISHED

Description

MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the unsanitized subject is rendered, executing the script in the viewer's browser.