MyBB 1.8.7
SecurityMaintenance
code 1807
Full Package
Install a new MyBB forum or upgrade from older versions.
Changed Files
Upgrade from the previous version.
Upgrading to this Version
Before performing any upgrade, remember to backup your forum’s files and database and store them safely.
If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.
Follow the Upgrade Documentation for more detailed instructions.
Security Vulnerabilities Addressed (13)
Missing permission check in newreply.php
Possible XSS Injection in Mod CP logs
CWE-79
CVSS:3.1/PR:L
Reported by Starpaul20
MyBB Team
Possible XSS Injection when editing users in Mod CP
Possible XSS Injection when pruning logs in ACP
CWE-79
CVSS:3.1/PR:H
Reported by Devilshakerz
MyBB Team
Possibility of retrieving database details through templates
Disclosure of ACP path when sending mails from ACP
Issues Resolved (83)
View issues on GitHubChanged Files ()
Changed Language Files (15)
There are changes to 15 language file(s). Changed languages files can be cross-referenced from the list above.Changed Templates (40)
forumdisplayforumdisplay_inlinemoderationforumdisplay_nopermissionheaderincludemanagegroupmanagegroup_addusermanagegroup_inviteusermember_profilemember_profile_findpostsmember_profile_findthreadsmember_registermember_register_referrermemberlistmemberlist_searchmisc_imcenter_skypemisc_whoposted_postermodcp_banusermodcp_findusermodcp_warninglogspolls_editpollpost_attachments_attachmentpost_attachments_newprivate_advanced_searchprivate_send_autocompletereportreport_error_nomodalsearchsearch_results_posts_inlinemoderationsearch_results_posts_postsearch_results_threads_inlinemoderationshowthread_inlinemoderationusercp_currentavatarusercp_editlistsusercp_editlists_userusercp_subscriptionsvideo_dailymotion_embedvideo_metacafe_embedvideo_myspacetv_embedvideo_vimeo_embedvideo_yahoo_embed