MyBB 1.6.14 Released – Security & Maintenance Release

MyBB 1.6.14 is now available from the MyBB website and is a security and maintenance release.

What’s added/changed in this version?

This release fixes 5 vulnerabilities and 50 reported issues causing incorrect functionality of MyBB. Please be aware that to be able to provide easy to manage updates not all issues have been fixed in this version.

  • Vulnerabilities:
    • Medium Risk: Possibility of executing PHP code through settings – reported by GiantCrocodile
    • Low Risk: A XSS vulnerability in polls.php – reported by AntiPaste
    • Low Risk: A XSS vulnerability in portal.php – reported by AntiPaste
    • Low Risk: Password protected forums can be viewed from the portal – reported by Nathan Malcolm
    • Low Risk: Super moderators have more permissions than expected – reported by JordanMussi
  • Bugs fixed:

Please view the 1.6.14 changes on the Docs site for more information about the changes in this version.

Please note, that you do need to run the upgrade script for this version.

Upgrading from 1.6.13 and Other Versions

Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.

To upgrade, follow the Upgrading process. The upgrade script is required. There are changes to 10 language files. 9 templates have been changed or added.

If you’re using MyBB 1.6.12 or lower

Reporting MyBB security vulnerabilities

If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.

As always, you can send through security related messages on the MyBB website from the Contact Us page or in our Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see.

Thanks,

MyBB Team

10 thoughts on “MyBB 1.6.14 Released – Security & Maintenance Release

  1. Thanks it’s great to know about this changes but do you fix on upgrade running on forums with rules, beause have an SQL Error if you run upgrade script with 1.6.13 and others.

  2. I don’t understand….. i’m using the 1.6.12 version and want to upgrade to 1.6.14.
    Do i need to run the upgrade script or not?

      • Ok, but in the statement appears in red that script upgrade is not needed. That was my confusion. Thanks for your quick answer.

      • The red message states that you have to run upgrade script (there is no “not”). It’s actually the same sentence used in many previous announcements.

Comments are closed.