216.73.216.40

CVE-2018-25247

· Published 04/04/2026 14:16 · Modified 04/04/2026 14:16

Labels: CVE-2018-25247 2026-04-04CVE-2018-25247CWE-79[email protected]

Essential information

Published
04/04/2026 14:16
Modified
04/04/2026 14:16
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profile, where liked posts are displayed without sanitization.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mybb / like plugin cpe:2.3:a:mybb:like_plugin:3.0.0:*:*:*:*:*:*:*

References