MyBB Thread Redirect Plugin Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting vulnerability has been identified in the MyBB Thread Redirect Plugin version 0.2.1. The issue arises in the custom text input field for thread redirects, where attackers can inject malicious SVG scripts. These scripts are executed when other users view the thread, potentially allowing for arbitrary script execution.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user viewing the thread.

Reproduction

To reproduce this vulnerability, create a new thread and enter any subject and redirect URL. In the message field, input a payload such as a SVG image with an 'onload' event. When the thread is viewed, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Jan 23, 2026, 5:45 PM
Updated: Jan 23, 2026, 5:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.8
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.