CVE-2023-53979
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
22/12/2025
Last modified:
27/12/2025
Description
MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mybb:mybb:1.8.32:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



