Description SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. Remediation References CVE-2021-27890 Related Vulnerabilities WordPress Plugin Schreikasten 'name' or 'contact' Field Cross-Site Scripting (0.14.13) WordPress Plugin WP Mega Menu Unspecified Vulnerability (1.4.1) Mailman Other Vulnerability (CVE-2002-0388) Drupal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-3223) WordPress Plugin Print, PDF, Email by PrintFriendly Multiple Cross-Site Scripting Vulnerabilities (3.3.7) Severity High Classification CVE-2021-27890 CWE-138 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities