Vulnerability Description
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the `Click here if you don't want to wait any longer` link because $force_redirect is true, allowing script execution when a victim selects the link. This issue is fixed in version 1.8.40.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/mybb/mybb/releases/tag/mybb_1840
- https://github.com/mybb/mybb/security/advisories/GHSA-wf92-5q5h-qr53
- https://mybb.com/versions/1.8.40
FAQ
What is CVE-2026-45118?
CVE-2026-45118 is a vulnerability with a CVSS score of 9.3 (CRITICAL). MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code inj...
How severe is CVE-2026-45118?
CVE-2026-45118 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45118?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.