CVE-2025-48940
Last modified
CVE-2025-48940 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the installer must be unlocked (no `install/lock` file present) and the upgrade script must be accessible (by re-installing the forum via access to `install/index.php`; when the forum has not yet been installed; or the attacker is authenticated as a forum administrator). MyBB 1.8.39 resolves this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Mybb | < 1.8.39 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-48940?
How severe is CVE-2025-48940?
How do I fix CVE-2025-48940?
Are you affected by CVE-2025-48940?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
