CVE-2025-29460
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Apr 17, 2025
Updated: Apr 25, 2025
CWE ID 918
Summary
CVE-2025-29460 is a vulnerability affecting MyBB 1.8.38 that permits a remote attacker to extract sensitive data through the Add Mycode function. Despite the vendor's disagreement, this issue grants unauthorized access to confidential information due to insufficient input validation and potential Server Side Request Forgery (SSRF) attacks. This vulnerability poses a significant risk to affected installations and necessitates immediate patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MyBB
Affected Vendors
- myBB