MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass CAPTCHA controls through challenge replay. The successful validation paths in contact.php, member.php?action=do_resendactivation, member.php?action=do_lostpw, member.php?action=do_emailuser, and sendthread.php?action=do_sendtofriend do not call captcha::invalidate_captcha() for the MyBB Default CAPTCHA selected by the captchaimage setting. A valid response can therefore be reused until a non-vulnerable endpoint invalidates it, an incorrect response is submitted, or the challenge expires. This issue is fixed in version 1.8.40.
We have discovered 1,463 live websites that are affected by CVE-2026-45734.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 1,463 live websites (100% of MyBB install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 21 versions ( 100% of all versions) |
| 552 websites | |
| 377 websites | |
| 130 websites | |
| 76 websites | |
| 37 websites | |
| 25 websites | |
| 23 websites | |
| 22 websites | |
| 18 websites | |
| 18 websites |
| .com | 535 websites |
| .de | 268 websites |
| .net | 152 websites |
| .org | 91 websites |
| .pl | 87 websites |
| .eu | 32 websites |
| .ru | 23 websites |
| .it | 18 websites |
| .info | 13 websites |
| .fr | 13 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.****.com | **,*** | ||
| ******.******.org | **,*** | ||
| *****.****.tv | ***,*** | ||
| ********.pl | ***,*** | ||
| *************.org | ***,*** | ||
| *************.net | ***,*** | ||
| ************.pl | ***,*** | ||
| ********.net | ***,*** | ||
| **********.org | ***,*** | ||
| *******.com | ***,*** |
FAQ