Skip to main content

Vendor archive

phpbb CVEs

Beta · best-effort

67 CVEs tagged to vendor phpbb5 Critical, 26 High, 35 Medium, 1 Low, 0 Unrated.

CVE-2026-29199

Published May 4, 2026

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-70811

Published Apr 9, 2026

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70810

Published Apr 9, 2026

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5917

Published Nov 2, 2023

A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of th…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-8226

Published Aug 17, 2020

A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16108

Published Mar 20, 2020

phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16107

Published Mar 11, 2020

Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5502

Published Jan 15, 2020

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5501

Published Jan 15, 2020

phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16993

Published Sep 30, 2019

In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13376

Published Sep 27, 2019

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11767

Published May 5, 2019

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9826

Published May 2, 2019

The fulltext search component in phpBB before 3.2.6 allows Denial of Service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19274

Published Nov 17, 2018

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000419

Published Jan 2, 2018

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3880

Published Sep 19, 2017

Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing at…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1432

Published Feb 10, 2015

The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1431

Published Feb 10, 2015

Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to "Rela…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1630

Published May 19, 2010

Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global annou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1627

Published May 19, 2010

feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7143

Published Sep 1, 2009

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6507

Published Mar 23, 2009

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6506

Published Mar 23, 2009

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 67 CVEsPage 1 of 3