In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
No PoCs from references.
- https://github.com/ahmetaltuntas/CVE-2023-28467
- https://github.com/nomi-sec/PoC-in-GitHub