Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NSummary
CVE-2026-45118 is a critical-severity Improper Neutralization of Script in Attributes in a Web Page (CWE-83) vulnerability in Mybb (inferred from references). Its CVSS base score is 9.3 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Content Injection (T1659); ranked at the 32th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SI-15 (Information Output Filtering) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-61021
Vulnerability Data
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the…
more
from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the `Click here if you don't want to wait any longer` link because $force_redirect is true, allowing script execution when a victim selects the link. This issue is fixed in version 1.8.40.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.3.4
Mitigating Controls (NIST 800-53 r5) AI
Input validation can reject or sanitize dangerous javascript: URIs and event-handler attributes before they reach rendered pages.
Output filtering directly neutralizes script content in HTML attributes, stopping the exact injection vector described by the CWE.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require output encoding and attribute neutralization to prevent this class of XSS.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure coding standards require proper escaping of untrusted data in HTML attributes, directly eliminating CWE-83.
Security testing in development catches attribute-injection flaws before release but does not itself implement the fix.
Secure SDLC mandates input validation and output encoding that directly prevents script injection in HTML attributes.
Application security requirements explicitly call for controls against injection flaws including attribute-based script injection.
Secure architecture principles reduce attack surface but do not prescribe the specific neutralization techniques needed.