MyBB Last User's Threads in Profile Plugin Persistent Cross-Site Scripting Vulnerability

Vulnerability

A persistent cross-site scripting vulnerability has been identified in the MyBB Last User's Threads in Profile Plugin version 1.2. This vulnerability allows attackers to inject malicious scripts by crafting thread subjects that include script tags. The injected scripts are executed when users visit the profile page of the thread creator.

Impact

Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user viewing the profile.

Reproduction

To reproduce this vulnerability, create a thread with a subject that includes a script tag, such as one containing JavaScript code, such as an alert. Once the thread is created, the script will execute when the profile page is visited.

Remediation

Users can update to the patched version of the plugin, which is available on the MyBB Community site.

Added: Apr 4, 2026, 2:19 PM
Updated: Apr 4, 2026, 2:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
5.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.