Description
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin DMSGuestbook Multiple Remote Vulnerabilities (1.8.0)
WordPress Plugin WordPress Photo Gallery by Gallery Bank Cross-Site Scripting (3.0.228)
WordPress Plugin Delete All Comments Easily Cross-Site Request Forgery (1.3)
Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2025-43766)