MyBB 1.6.16

Security

This version is no longer supported

The MyBB 1.6 series reached end of life on October 1, 2015.

This means there will be no more security or maintenance releases for this series and forums running this version of MyBB may be at risk of unfixed security issues. The MyBB Group strongly encourages all communities to upgrade to the latest release of MyBB as soon as possible.

Security vulnerabilities addressed (5)

Low risk

A XSS vulnerability related to post icons

Reported by Destroy666)

Low risk

A XSS vulnerability in admin/modules/style/templates.php

Low risk

A XSS vulnerability in admin/modules/config/languages.php

Low risk

unserialize may call PHP magic methods

Reported by chtg)

Low risk

PHP setting request_order can break register globals handling

Reported by chtg)

Changed Files (9)

  • admin - modules - config - languages.php - plugins.php - settings.php - home - version_check.php - style - templates.php - themes.php - tools - file_verification.php - index.php
  • inc - class_core.php - functions.php
  • calendar.php
  • forumdisplay.php
  • portal.php
  • private.php
  • search.php
  • showthread.php
  • usercp.php