Description
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
Remediation
References
Related Vulnerabilities
Dolphin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3728)
WordPress 5.4.x Directory Traversal (5.4 - 5.4.15)
WordPress Plugin WP Maintenance Mode Cross-Site Request Forgery (1.8.7)
WordPress Plugin External 'Video for Everybody' Cross-Site Scripting (2.0)
WordPress 4.1.x Possible SQL Injection Vulnerability (4.1 - 4.1.19)