CVE-2026-45115 | MyBB up to 1.8.39 Buddy/Ignore usercp.php htmlspecialchars_uni Username cross site scripting
A vulnerability identified as problematic has been detected in MyBB up to 1.8.39. Affected by this issue is the function htmlspecialchars_uni of the file usercp.php of the component Buddy/Ignore. The manipulation of the argument Username leads to cross site scripting.
This vulnerability is traded as CVE-2026-45115. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More