← Vulnerability feed

Vulnerability record · CVE-2006-3420 · published 7 July 2006

CVE-2006-3420: Mybulletinboard vulnerability

Mybulletinboard · Mybulletinboard

Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

7.5 CVSS 2.0 High EPSS 1.5% · top 26.2%
7.5CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3420 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-4200Mybulletinboard vulnerabilityMultiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities …EPSS 2.2%7.5CVE-2009-2230Mybulletinboard sql injection vulnerabilitySQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbi…EPSS 1.2%7.5CVE-2008-0382Mybulletinboard code injection vulnerabilityMultiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) f…EPSS 42%7.5CVE-2007-2211Mybulletinboard vulnerabilitySQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands…EPSS 1.1%7.5CVE-2007-1963Mybb vulnerabilitySQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attacke…EPSS 1.3%7.5CVE-2006-3775Mybulletinboard sql injection vulnerabilitySQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrar…EPSS 2.5%7.5CVE-2006-3758Mybulletinboard vulnerabilityinc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variable…EPSS 1.3%7.5CVE-2006-3760Mybulletinboard vulnerabilityMultiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified v…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2006-3420), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.