CRITICAL 9.3 CVE-2026-45118 Published 18 Aug 2026

MyBB Contact Module Open Redirect and Reflected JavaScript Injection Vulnerability

Worried this affects your website?

MyBB forum software prior to version 1.8.40 contains an open redirect and reflected JavaScript code injection vulnerability in the Contact module.

The contact.php script accepts a redirect target from the 'from' HTTP parameter or the 'Referer' HTTP header and passes it to redirect() without sufficient verification. A javascript: URI can become the target of the 'Click here if you don't want to wait any longer' link because $force_redirect is true, allowing script execution when a victim selects the link.

  • Affected versions: MyBB before 1.8.40
  • Attack vector: crafted 'from' parameter or 'Referer' header
  • Impact: open redirect and reflected JavaScript execution

This issue is fixed in version 1.8.40.

Reference: CVE-2026-45118 on NVD

← Back to Security News