CVE

CVE-2021-41866

CVE-2021-41866

MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP’s theme management is not escaped properly.

Source: CVE-2021-41866

Exit mobile version