PT-2026-4502 · Mybb · Trending Widget

Published

2026-01-23

·

Updated

2026-01-23

·

CVE-2018-25132

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-25132

Affected Products

Trending Widget