MyBB My Arcade Plugin Persistent Cross-Site Scripting Vulnerability

Vulnerability

A persistent cross-site scripting vulnerability has been identified in the MyBB My Arcade Plugin version 1.3. This vulnerability allows authenticated users to inject malicious scripts into arcade game score comments. The injected HTML and JavaScript payloads are executed when other users view or edit the comments.

Impact

Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user viewing the comment.

Reproduction

To reproduce this vulnerability, an authenticated user must play an arcade game and then add a comment to their score containing a script payload, such as a JavaScript alert. Once the comment is saved, editing the comment will trigger the execution of the injected script.

Remediation

Users are advised to update the My Arcade Plugin to version 1.3.1.

Added: Apr 4, 2026, 2:21 PM
Updated: Apr 4, 2026, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
5.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.