Eklenti güvenlik geçmişi
Mang Board güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Mang Board eklentisi için 8 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 6 tanesi kritik veya yüksek önemde, 6 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.4.3.
- Toplam kayıt
- 8
- Kritik veya yüksek
- 6
- Oturumsuz istismar
- 6
- Son kayıt
- 2 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.4.2 ve öncesi · Oturum açmadan istismar edilebilir
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.
Türkçe kayıt ve ne yapmalısiteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.4.1 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 2.3.8 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
eksik yetki denetimi
Etkilenen sürümler: 2.3.7 ve öncesi
The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_auth_cookie(). This makes it possible for authenticated attackers, with subscriber-level access and above, to forge administrator authentication cookies and change administrator passwords to achieve complete site takeover.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.3.4 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.3.4 ve öncesi · Oturum açmadan istismar edilebilir
The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.8.6 ve öncesi
The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.8.4 ve öncesi · Oturum açmadan istismar edilebilir
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kitae Park Mang Board WP mangboard allows Reflected XSS.This issue affects Mang Board WP: from n/a through <= 1.8.4.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.