CVE-2026-45115

MyBB: Buddy/ignore list username XSS

MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload is triggered when a victim chooses Yes in Please Confirm while removing the username in usercp.php, or selects the username through the onclick handler in the xmlhttp.php Select Buddies popup. The uniquely identifying implementation details include Private Messages Select Buddies list, and unescaped single quotes. This issue is fixed in version 1.8.40.


We have discovered 1,463 live websites that are affected by CVE-2026-45115.

Run a Free Instant Scan




Affected Software

Product  MyBB
Category Message Boards
Vulnerable Domains1,463 live websites (100% of MyBB install base)
Vulnerable Versions
  • from 0 through 1.8.40
Vulnerable Versions Count21 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Website Distribution by Country

Number of websites using CVE-2026-45115
United States552 websites



Germany377 websites
Poland130 websites
France76 websites
GB37 websites
Turkey25 websites
Netherlands23 websites
Italy22 websites
Iran18 websites
Russia18 websites

Website Distribution by TLD

Number of websites using CVE-2026-45115
.com535 websites
.de268 websites
.net152 websites
.org91 websites
.pl87 websites
.eu32 websites
.ru23 websites
.it18 websites
.info13 websites
.fr13 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-45115

Top websites that are affected by CVE-2026-45115. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.****.com United States**,***
******.******.org United States**,***
*****.****.tv United States***,***
********.pl Poland***,***
*************.org Laos***,***
*************.net United States***,***
************.pl Poland***,***
********.net United States***,***
**********.org United States***,***
*******.com United States***,***
See full domain list

FAQ

CVE-2026-45115 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MyBB
A total of 1,463 websites have been identified as vulnerable to CVE-2026-45115, based on global website indexing conducted by WebTechSurvey.
The MyBB is affected by the CVE-2026-45115 vulnerability.
MyBB versions up to 1.8.40 are vulnerable to CVE-2026-45115.
CVE-2026-45115 is resolved in version 1.8.40 of MyBB.