Back

CVE-2015-8974

CRITICAL

SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: Jan 31, 2017 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (8)

Vendor Product Version
mybb merge_system *
mybb mybb *
mybb mybb 1.8.0
mybb mybb 1.8.1
mybb mybb 1.8.2
mybb mybb 1.8.3
mybb mybb 1.8.4
mybb mybb 1.8.5

GitHub Security Advisory GHSA-9wjc-jp2f-45cq

SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB ...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 2.12%

Top 20% most likely to be exploited

Threat Score 40.6 / 100

Data Sources

NVD EPSS GitHub