phpBB records
67 published records for vendor phpbb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 34
- With a fix record
- 25.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
67 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2006-7148Proof of concept | PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to ephpbb · maluinfo | Critical10.0 | — | 3.4% | Mar 7, 2007 |
41Plan | CVE-2006-7174No exploit | PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrphpbb · dimension | Critical10.0 | — | 2.2% | Mar 21, 2007 |
40Plan | CVE-2008-1766No exploit | Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related buphpbb · phpbb | Critical10.0 | — | 1.5% | Apr 12, 2008 |
40Plan | CVE-2008-3224No exploit | Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used wiphpbb · phpbb | Critical10.0 | — | 1.5% | Jul 18, 2008 |
38Monitor | CVE-2007-3935Proof of concept | PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary phpbb · supanav | Critical9.3 | — | 4.0% | Jul 20, 2007 |
37Monitor | CVE-2001-1471Proof of concept | prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prphpbb · phpbb · CWE-665 | High8.8 | — | 7.7% | Jul 31, 2001 |
35Monitor | CVE-2019-16993No exploit | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Cphpbb · phpbb · CWE-352 | High8.8 | — | 0.8% | Sep 30, 2019 |
35Monitor | CVE-2025-70810No exploit | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function anphpbb · phpbb · CWE-352 | High8.8 | — | 0.2% | Apr 9, 2026 |
32Monitor | CVE-2006-7168Proof of concept | PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary phpbb · phpbb | High7.5 | — | 7.3% | Mar 20, 2007 |
32Monitor | CVE-2026-29199No exploit | phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning.phpbb · phpbb · CWE-640 | High8.1 | — | 0.4% | May 4, 2026 |
31Monitor | CVE-2007-0761Proof of concept | PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrarphpbb · ezboard converter | High7.5 | — | 3.3% | Feb 5, 2007 |
31Monitor | CVE-2006-5309Proof of concept | PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phphpbb · prillian french | High7.5 | — | 3.3% | Oct 17, 2006 |
31Monitor | CVE-2006-6593Proof of concept | PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP cophpbb · amazonia mod | High7.5 | — | 2.4% | Dec 15, 2006 |
31Monitor | CVE-2007-1961Proof of concept | PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute phpbb · mutant | High7.5 | — | 2.3% | Apr 11, 2007 |
31Monitor | CVE-2008-1565Proof of concept | Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbiphpbb · pjirc module · CWE-22 | High7.5 | — | 2.3% | Mar 31, 2008 |
31Monitor | CVE-2008-1512Proof of concept | Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers phpbb · module xs · CWE-22 | High7.5 | — | 2.3% | Mar 25, 2008 |
31Monitor | CVE-2002-2287Proof of concept | PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to exphpbb · advanced quick reply hack · CWE-94 | High7.5 | — | 2.3% | Dec 31, 2002 |
31Monitor | CVE-2006-5312Proof of concept | PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to ephpbb · ajax shoutbox | High7.5 | — | 2.2% | Oct 17, 2006 |
31Monitor | CVE-2019-9826No exploit | The fulltext search component in phpBB before 3.2.6 allows Denial of Service.phpbb · phpbb · CWE-20 | High7.5 | — | 2.0% | May 2, 2019 |
30Monitor | CVE-2018-19274No exploit | Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phaphpbb · phpbb · CWE-502 | High7.2 | — | 5.2% | Nov 17, 2018 |
30Monitor | CVE-2017-1000419No exploit | phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting phpbb · phpbb · CWE-918 | High7.5 | — | 1.3% | Jan 2, 2018 |
30Monitor | CVE-2010-1630No exploit | Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in cphpbb · phpbb | High7.5 | — | 1.2% | May 19, 2010 |
30Monitor | CVE-2019-16108No exploit | phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.phpbb · phpbb · CWE-94 | High7.5 | — | 1.1% | Mar 19, 2020 |
30Monitor | CVE-2003-1530Proof of concept | SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the markphpbb · phpbb · CWE-89 | High7.5 | — | 1.1% | Dec 31, 2003 |
30Monitor | CVE-2007-4653Proof of concept | SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute phpbb · phpbb · CWE-89 | High7.5 | — | 1.0% | Sep 4, 2007 |
- CVE-2006-714841Plan
PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to e
CriticalCVSS 10.0Proof of conceptEPSS 3%phpbb · maluinfoMar 7, 2007
- CVE-2006-717441Plan
PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitr
CriticalCVSS 10.0No exploitEPSS 2%phpbb · dimensionMar 21, 2007
- CVE-2008-176640Plan
Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bu
CriticalCVSS 10.0No exploitEPSS 1%phpbb · phpbbApr 12, 2008
- CVE-2008-322440Plan
Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used wi
CriticalCVSS 10.0No exploitEPSS 1%phpbb · phpbbJul 18, 2008
- CVE-2007-393538Monitor
PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary
CriticalCVSS 9.3Proof of conceptEPSS 4%phpbb · supanavJul 20, 2007
- CVE-2001-147137Monitor
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr
HighCVSS 8.8Proof of conceptEPSS 8%phpbb · phpbbJul 31, 2001
- CVE-2019-1699335Monitor
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration C
HighCVSS 8.8No exploitEPSS 1%phpbb · phpbbSep 30, 2019
- CVE-2025-7081035Monitor
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function an
HighCVSS 8.8No exploitEPSS 0%phpbb · phpbbApr 9, 2026
- CVE-2006-716832Monitor
PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 7%phpbb · phpbbMar 20, 2007
- CVE-2026-2919932Monitor
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning.
HighCVSS 8.1No exploitEPSS 0%phpbb · phpbbMay 4, 2026
- CVE-2007-076131Monitor
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrar
HighCVSS 7.5Proof of conceptEPSS 3%phpbb · ezboard converterFeb 5, 2007
- CVE-2006-530931Monitor
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for ph
HighCVSS 7.5Proof of conceptEPSS 3%phpbb · prillian frenchOct 17, 2006
- CVE-2006-659331Monitor
PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP co
HighCVSS 7.5Proof of conceptEPSS 2%phpbb · amazonia modDec 15, 2006
- CVE-2007-196131Monitor
PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute
HighCVSS 7.5Proof of conceptEPSS 2%phpbb · mutantApr 11, 2007
- CVE-2008-156531Monitor
Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbi
HighCVSS 7.5Proof of conceptEPSS 2%phpbb · pjirc moduleMar 31, 2008
- CVE-2008-151231Monitor
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers
HighCVSS 7.5Proof of conceptEPSS 2%phpbb · module xsMar 25, 2008
- CVE-2002-228731Monitor
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to ex
HighCVSS 7.5Proof of conceptEPSS 2%phpbb · advanced quick reply hackDec 31, 2002
- CVE-2006-531231Monitor
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to e
HighCVSS 7.5Proof of conceptEPSS 2%phpbb · ajax shoutboxOct 17, 2006
- CVE-2019-982631Monitor
The fulltext search component in phpBB before 3.2.6 allows Denial of Service.
HighCVSS 7.5No exploitEPSS 2%phpbb · phpbbMay 2, 2019
- CVE-2018-1927430Monitor
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Pha
HighCVSS 7.2No exploitEPSS 5%phpbb · phpbbNov 17, 2018
- CVE-2017-100041930Monitor
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting
HighCVSS 7.5No exploitEPSS 1%phpbb · phpbbJan 2, 2018
- CVE-2010-163030Monitor
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in c
HighCVSS 7.5No exploitEPSS 1%phpbb · phpbbMay 19, 2010
- CVE-2019-1610830Monitor
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
HighCVSS 7.5No exploitEPSS 1%phpbb · phpbbMar 19, 2020
- CVE-2003-153030Monitor
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark
HighCVSS 7.5Proof of conceptEPSS 1%phpbb · phpbbDec 31, 2003
- CVE-2007-465330Monitor
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute
HighCVSS 7.5Proof of conceptEPSS 1%phpbb · phpbbSep 4, 2007