MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-15596
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page one can generate a URL such as http://localhost/syndication.phpfidamptypeatom1.0amplimit15. The thread titles (within title elements of the generated XML documents) aren39t sanitized leading to XSS.