PT-2026-30367 · Mybb · Thankyou/Like System

Published

2026-04-04

·

Updated

2026-04-04

·

CVE-2018-25247

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the unsanitized subject is rendered, executing the script in the viewer's browser.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-25247

Affected Products

Thankyou/Like System