Security Advisory

CVE-2021-41866

5.4
MEDIUM

Vulnerability Description

MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
Published Date October 26, 2021
Official Source NIST NVD Advisory