MyBB 1.8.19

SecurityMaintenance

code 1819

Full Package

Install a new MyBB forum or upgrade from older versions.

.zip – 2.16 MB

Download from MyBB.com Download from GitHub.com (mirror)

sha512:

9a1209195f62fca692e4c0ee0869e66ba24598f05e64a666059e23df00fc43a42ec622a57c4939b1ae5c157b199199ea5b3efe5d5570ff210ea9e1f873c491c4

More checksums…

sha256:

af2b1e088ff198da27b824cd0d198d1b5c4354a312f996449f3a81e8e7fa5c81

sha1:

cf9b927c1015ccff349f3dcece23f884fd9ed644

md5:

a6ab544e648a6b7ee33b2d979f441fd9

Changed Files

Upgrade from the previous version.

.zip – 0.46 MB

Download from MyBB.com Download from GitHub.com (mirror)

sha512:

bec78edc083726aeb70a7357c5570c32ad5dc8da58348b120617b49b2a31b0026b09b487e61a81bf9294600e138d79ab048efe4a9848e62c4ab6314ea310457e

More checksums…

sha256:

679b5f46d126e3de4e120168920605a8d203788816cf66860a5eb00ac454b2c6

sha1:

56618019355f8a16f7e9f89032c6cdd36a4f70f4

md5:

6ab84d6390bad2f2afdd11445ab6b886

How to verify packages

This update includes improved compatibility with PostgreSQL and resolves regressions from previous versions. Administrators may need to update CSS code in global.css for customized themes.

Upgrading to this Version

To upgrade: copy and overwrite the files, and run the install/ upgrade script.

Before performing any upgrade, remember to backup your forum’s files and database and store them safely.

If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.

Follow the Upgrade Documentation for more detailed instructions.

Security Vulnerabilities Addressed (4)

High risk

Email field SQL Injection

CWE-89 CVSS:3.1/PR:N Reported by StefanT

Medium risk

Video MyCode Persistent XSS in Visual Editor

CWE-79 CVSS:3.1/PR:N Reported by Numan OZDEMIR InfinitumIT

Low risk

Insufficient permission check in User CP's attachment management

CWE-284 CVSS:3.1/PR:L Reported by StefanT

Low risk

Insufficient email address verification

CWE-345 CVSS:3.1/PR:L Reported by StefanT

Issues Resolved (8)

View issues on GitHub

Changed Files ()

Changed Templates (2)

  • codebuttons
  • post_subscription_method