Skip to content
Noroxi

phpBB records

67 published records for vendor phpbb.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

67 records
  • PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to e

    CriticalCVSS 10.0Proof of conceptEPSS 3%

    phpbb · maluinfoMar 7, 2007

  • PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitr

    CriticalCVSS 10.0No exploitEPSS 2%

    phpbb · dimensionMar 21, 2007

  • Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bu

    CriticalCVSS 10.0No exploitEPSS 1%

    phpbb · phpbbApr 12, 2008

  • Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used wi

    CriticalCVSS 10.0No exploitEPSS 1%

    phpbb · phpbbJul 18, 2008

  • CVE-2007-3935
    38Monitor

    PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary

    CriticalCVSS 9.3Proof of conceptEPSS 4%

    phpbb · supanavJul 20, 2007

  • CVE-2001-1471
    37Monitor

    prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr

    HighCVSS 8.8Proof of conceptEPSS 8%

    phpbb · phpbbJul 31, 2001

  • In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration C

    HighCVSS 8.8No exploitEPSS 1%

    phpbb · phpbbSep 30, 2019

  • Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function an

    HighCVSS 8.8No exploitEPSS 0%

    phpbb · phpbbApr 9, 2026

  • CVE-2006-7168
    32Monitor

    PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary

    HighCVSS 7.5Proof of conceptEPSS 7%

    phpbb · phpbbMar 20, 2007

  • phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning.

    HighCVSS 8.1No exploitEPSS 0%

    phpbb · phpbbMay 4, 2026

  • CVE-2007-0761
    31Monitor

    PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrar

    HighCVSS 7.5Proof of conceptEPSS 3%

    phpbb · ezboard converterFeb 5, 2007

  • CVE-2006-5309
    31Monitor

    PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for ph

    HighCVSS 7.5Proof of conceptEPSS 3%

    phpbb · prillian frenchOct 17, 2006

  • CVE-2006-6593
    31Monitor

    PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP co

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpbb · amazonia modDec 15, 2006

  • CVE-2007-1961
    31Monitor

    PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpbb · mutantApr 11, 2007

  • CVE-2008-1565
    31Monitor

    Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbi

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpbb · pjirc moduleMar 31, 2008

  • CVE-2008-1512
    31Monitor

    Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpbb · module xsMar 25, 2008

  • CVE-2002-2287
    31Monitor

    PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to ex

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpbb · advanced quick reply hackDec 31, 2002

  • CVE-2006-5312
    31Monitor

    PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to e

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpbb · ajax shoutboxOct 17, 2006

  • CVE-2019-9826
    31Monitor

    The fulltext search component in phpBB before 3.2.6 allows Denial of Service.

    HighCVSS 7.5No exploitEPSS 2%

    phpbb · phpbbMay 2, 2019

  • Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Pha

    HighCVSS 7.2No exploitEPSS 5%

    phpbb · phpbbNov 17, 2018

  • phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting

    HighCVSS 7.5No exploitEPSS 1%

    phpbb · phpbbJan 2, 2018

  • CVE-2010-1630
    30Monitor

    Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in c

    HighCVSS 7.5No exploitEPSS 1%

    phpbb · phpbbMay 19, 2010

  • phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

    HighCVSS 7.5No exploitEPSS 1%

    phpbb · phpbbMar 19, 2020

  • CVE-2003-1530
    30Monitor

    SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpbb · phpbbDec 31, 2003

  • CVE-2007-4653
    30Monitor

    SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpbb · phpbbSep 4, 2007