Known Vulnerabilities for New Threads by Mybb
Listed below are 1 of the newest known vulnerabilities associated with "New Threads" by "Mybb".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55205 json | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/s... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54905 json | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly gr... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-54651 json | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-54224 json | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on ins... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54223 json | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file o... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54222 json | UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to intera... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54221 json | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling atta... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54220 json | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an atta... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54219 json | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize us... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-53673 json | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticat... | Not Provided | 2026-06-10 | 2026-06-10 |