Total vulnerabilities in the database
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: