← Vulnerability feed

Vulnerability record · CVE-2022-24734 · published 9 March 2022

CVE-2022-24734: MyBB Admin CP settings module type validation flaw enables RCE

Mybb · Mybb

MyBB's Admin CP Settings management module fails to validate setting types on insertion and update, allowing a setting of type `php` containing PHP code to be stored. That code executes on Change Settings pages, yielding remote code execution. The flaw affects MyBB versions before 1.8.30 and requires Admin CP access with the `Can manage settings?` permission.

7.2 CVSS 3.1 High EPSS 78% · top 0.4% CWE-94 · Code injection
7.2CVSS 3.1 base score, v2 6.5
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. This results in a Remote Code Execution (RCE) vulnerability. The vulnerable module requires Admin CP access with the `Can manage settings?` permission. MyBB's Settings module, which allows administrators to add, edit, and delete non-default settings, stores setting data in an options code string ($options_code; mybb_settings.optionscode database column) that identifies the setting type and its options, separated by a new line character (\n). In MyBB 1.2.0, support for setting type php was added, for which the remaining part of the options code is PHP code executed on Change Settings pages (reserved for plugins and internal use). MyBB 1.8.30 resolves this issue. There are no known workarounds.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw gives authenticated administrators code execution, public exploit code exists, and EPSS is very high, though exploitation requires prior Admin CP access with a specific permission.

What it is

MyBB's Admin CP Settings management module fails to validate setting types on insertion and update, allowing a setting of type `php` containing PHP code to be stored. That code executes on Change Settings pages, yielding remote code execution. The flaw affects MyBB versions before 1.8.30 and requires Admin CP access with the `Can manage settings?` permission.

Impact

An attacker with the required admin permission gains arbitrary PHP code execution on the forum server, leading to full compromise of the web application and its data. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the Admin CP Settings management module; the attacker must already hold Admin CP access with the `Can manage settings?` permission, and no user interaction is required. The CVSS vector is AV:N/AC:L/PR:H/UI:N.

Exploitation

Public exploit code is referenced by Packet Storm advisories, and EPSS is 0.77827 (99.5th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Upgrade MyBB to 1.8.30 or later, which resolves the issue.
  • Restrict Admin CP access and the `Can manage settings?` permission to the smallest possible set of trusted accounts.
  • Audit existing settings for unexpected `php` type entries or injected code in the optionscode column.
  • Monitor and alert on changes to MyBB settings, especially additions or edits of non-default settings.
  • Apply the vendor patch commit and advisory guidance; the record states there are no known workarounds.

Detection

  • Review the mybb_settings.optionscode column for settings of type `php` or unexpected PHP code.
  • Monitor Admin CP audit or access logs for settings creation and update actions by unusual accounts.
  • Hunt for unexpected PHP execution or file changes on the forum host correlated with Change Settings page access.
  • Alert on administrative logins or permission changes involving the `Can manage settings?` capability.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24734 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-10018Mybb code injection vulnerabilitymyBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitr…EPSS 2.0%10.0CVE-2015-8974Mybb merge system sql injection vulnerabilitySQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.…EPSS 2.1%10.0CVE-2015-2786Mybb vulnerabilityUnspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to …EPSS 1.4%10.0CVE-2011-5133Mybb vulnerabilityUnspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."EPSS 1.7%10.0CVE-2006-0218Mybb vulnerabilityMultiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate…EPSS 1.2%9.8CVE-2020-22612Mybb code injection vulnerabilityInstaller RCE on settings file write in MyBB before 1.8.22.EPSS 0.73%9.8CVE-2017-16780Mybb cross-site request forgery vulnerabilityThe installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.EPSS 5.8%9.8CVE-2016-9402Mybb merge system sql injection vulnerabilitySQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote a…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2022-24734), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.