MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims visit affected profiles.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims visit affected profiles. | |
| Title | MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF | |
| First Time appeared |
Mybb
Mybb mybb |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:mybb:mybb:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Mybb
Mybb mybb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-16T15:26:03.991Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47934
No data.
Status : Received
Published: 2026-05-16T16:16:21.267
Modified: 2026-05-16T16:16:21.267
Link: CVE-2021-47934
No data.
OpenCVE Enrichment
Updated: 2026-05-16T17:00:13Z
Weaknesses