CVE-2021-41866
EUVD-2021-2886626.10.2021, 22:15
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mybb | mybb | 𝑥 < 1.8.28 |
𝑥
= Vulnerable software versions