myBB Forums 1.8.26 Stored Cross-Site Scripting via Template Management
No sign of exploitation. No public exploitation artifact known so far.
myBB Forums 1.8.26 has a vulnerability in its template management system that allows administrators to accidentally or maliciously insert harmful scripts into template titles. When other users view these templates, the scripts execute in their browsers, potentially stealing information or taking actions on their behalf.
Stored XSS vulnerability in myBB 1.8.26 template management system exploitable by authenticated administrators via the template title field in the Global Templates interface. Injected payloads persist in the database and execute in the context of users viewing the affected templates, requiring no user interaction beyond accessing the template management area.