Description
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
Remediation
References
Related Vulnerabilities
WordPress 4.0 Multiple Vulnerabilities (4.0)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Multiple Vulnerabilities (3.3.0)
Dolibarr Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-56588)
WordPress Plugin SendPress Newsletters Unspecified Vulnerability (1.7.6.11)