MyBB Timeline Plugin 1.0 contains cross-site scripting...
Moderate severity
Unreviewed
Published
May 16, 2026
to the GitHub Advisory Database
•
Updated May 16, 2026
Description
Published by the National Vulnerability Database
May 16, 2026
Published to the GitHub Advisory Database
May 16, 2026
Last updated
May 16, 2026
MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims visit affected profiles.
References