Back

MEDIUM

MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles

Published Apr 4, 2026

Description

MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the unsanitized subject is rendered, executing the script in the viewer's browser.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 4, 2026
Updated May 25, 2026
Reserved Apr 4, 2026
CISA Vulnrichment
Updated Apr 6, 2026
NVD
Status Modified
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a