CVE-2018-25248 MEDIUM

CVE-2018-25248: MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php

Vendor Mybb
Product MyBB Downloads Plugin
Weakness CWE-79 · XSS
Published April 4, 2026
Last update May 24, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

Description

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php.

Key dates

Disclosure timeline

April 4, 2026 CVE published
May 24, 2026 Record updated