phpBB / phpBB
119 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48613 | SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution… | HIGH | 7.1 | Jun 12, 2026 |
| CVE-2026-48612 | Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked… | HIGH | 8.0 | Jun 12, 2026 |
| CVE-2026-47366 | Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to… | HIGH | 7.2 | Jun 12, 2026 |
| CVE-2026-48611 | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access… | CRITICAL | 9.8 | Jun 12, 2026 |
| CVE-2026-29199 | phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostn… | HIGH | 8.1 | May 4, 2026 |
| CVE-2025-70811 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management… | MEDIUM | 4.3 | Apr 9, 2026 |
| CVE-2025-70810 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authenticatio… | HIGH | 8.8 | Apr 9, 2026 |
| CVE-2023-5917 | phpBB Smiley Pack acp_icons.php main cross site scripting | MEDIUM | 4.8 | Nov 2, 2023 |
| CVE-2020-8226 | A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF. | MEDIUM | 5.8 | Aug 17, 2020 |
| CVE-2019-16108 | phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode. | HIGH | 7.5 | Mar 19, 2020 |
| CVE-2019-16107 | Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments. | MEDIUM | 4.3 | Mar 11, 2020 |
| CVE-2020-5502 | phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships. | MEDIUM | 6.5 | Jan 14, 2020 |
| CVE-2020-5501 | phpBB 3.2.8 allows a CSRF attack that can modify a group avatar. | MEDIUM | 4.3 | Jan 14, 2020 |
| CVE-2011-0544 | phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag. | MEDIUM | 6.1 | Nov 13, 2019 |
| CVE-2019-16993 | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An ac… | HIGH | 8.8 | Sep 30, 2019 |
| CVE-2019-13376 | phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking… | MEDIUM | 6.5 | Sep 27, 2019 |
| CVE-2019-11767 | Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the r… | MEDIUM | 5.8 | May 5, 2019 |
| CVE-2019-9826 | The fulltext search component in phpBB before 3.2.6 allows Denial of Service. | HIGH | 7.5 | May 2, 2019 |
| CVE-2018-19274 | Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization w… | HIGH | 7.2 | Nov 17, 2018 |
| CVE-2017-1000419 | phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content an… | HIGH | 7.5 | Jan 2, 2018 |
| CVE-2015-3880 | Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and… | MEDIUM | 6.1 | Sep 19, 2017 |
| CVE-2015-1432 | The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers t… | MEDIUM | 6.8 | Feb 10, 2015 |
| CVE-2015-1431 | Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vect… | MEDIUM | 4.3 | Feb 10, 2015 |
| CVE-2010-1630 | Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances relate… | HIGH | 8.1 | May 19, 2010 |
| CVE-2010-1627 | feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions vi… | HIGH | 7.6 | May 19, 2010 |
Showing 1 to 25 of 119 CVEs