WPHizmet

Eklenti güvenlik geçmişi

Mang Board güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Mang Board eklentisi için 8 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 6 tanesi kritik veya yüksek önemde, 6 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.4.3.

Toplam kayıt
8
Kritik veya yüksek
6
Oturumsuz istismar
6
Son kayıt
2 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-96871Yüksek · 7,22 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.4.2 ve öncesi · Oturum açmadan istismar edilebilir

    The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-94176Yüksek · 7,123 Eylül 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.4.1 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.

  • CVE-2026-84770Yüksek · 8,82 Eylül 2026

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 2.3.8 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

  • CVE-2026-75977Yüksek · 8,826 Ağustos 2026

    eksik yetki denetimi

    Etkilenen sürümler: 2.3.7 ve öncesi

    The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_auth_cookie(). This makes it possible for authenticated attackers, with subscriber-level access and above, to forge administrator authentication cookies and change administrator passwords to achieve complete site takeover.

  • CVE-2026-61974Yüksek · 7,113 Ağustos 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.3.4 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.

  • CVE-2026-13334Orta · 6,19 Temmuz 2026

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 2.3.4 ve öncesi · Oturum açmadan istismar edilebilir

    The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVE-2025-3435Orta · 4,424 Nisan 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.8.6 ve öncesi

    The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

  • CVE-2024-56296Yüksek · 7,17 Ocak 2025

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.8.4 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kitae Park Mang Board WP mangboard allows Reflected XSS.This issue affects Mang Board WP: from n/a through <= 1.8.4.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.