PT-2025-23536 · Mybb · Mybb

Dvz

·

Published

2025-06-02

·

Updated

2025-06-02

·

CVE-2025-48941

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.39
Description The search component in MyBB does not validate permissions correctly, allowing attackers to determine the existence of hidden threads, including draft, unapproved, or soft-deleted threads, by analyzing the search results. The mybb threads.visible integer column is not validated in internal search queries, which can be used to output a general success or failure of the search. This issue can be exploited by users with access to the search functionality and general access to forums containing the threads. The vulnerability does not expose the message content of posts.
Recommendations For MyBB versions prior to 1.8.39, update to version 1.8.39 to resolve the issue. As a temporary workaround, consider restricting access to the search functionality to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-48941
GHSA-F847-57XC-FFWR

Affected Products

Mybb