phpbb kayıtları
phpbb üreticisine ait 67 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 34
- Düzeltme kaydı olan
- %25,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
67 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2006-7148Kavram kanıtı | PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to ephpbb · maluinfo | Kritik10,0 | — | %3,4 | 7 Mar 2007 |
41Planlayın | CVE-2006-7174İstismar yok | PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrphpbb · dimension | Kritik10,0 | — | %2,2 | 21 Mar 2007 |
40Planlayın | CVE-2008-1766İstismar yok | Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related buphpbb · phpbb | Kritik10,0 | — | %1,5 | 12 Nis 2008 |
40Planlayın | CVE-2008-3224İstismar yok | Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used wiphpbb · phpbb | Kritik10,0 | — | %1,5 | 18 Tem 2008 |
38İzleyin | CVE-2007-3935Kavram kanıtı | PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary phpbb · supanav | Kritik9,3 | — | %4,0 | 20 Tem 2007 |
37İzleyin | CVE-2001-1471Kavram kanıtı | prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prphpbb · phpbb · CWE-665 | Yüksek8,8 | — | %7,7 | 31 Tem 2001 |
35İzleyin | CVE-2019-16993İstismar yok | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Cphpbb · phpbb · CWE-352 | Yüksek8,8 | — | %0,8 | 30 Eyl 2019 |
35İzleyin | CVE-2025-70810İstismar yok | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function anphpbb · phpbb · CWE-352 | Yüksek8,8 | — | %0,2 | 9 Nis 2026 |
32İzleyin | CVE-2006-7168Kavram kanıtı | PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary phpbb · phpbb | Yüksek7,5 | — | %7,3 | 20 Mar 2007 |
32İzleyin | CVE-2026-29199İstismar yok | phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning.phpbb · phpbb · CWE-640 | Yüksek8,1 | — | %0,4 | 4 May 2026 |
31İzleyin | CVE-2007-0761Kavram kanıtı | PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrarphpbb · ezboard converter | Yüksek7,5 | — | %3,3 | 5 Şub 2007 |
31İzleyin | CVE-2006-5309Kavram kanıtı | PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phphpbb · prillian french | Yüksek7,5 | — | %3,3 | 17 Eki 2006 |
31İzleyin | CVE-2006-6593Kavram kanıtı | PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP cophpbb · amazonia mod | Yüksek7,5 | — | %2,4 | 15 Ara 2006 |
31İzleyin | CVE-2007-1961Kavram kanıtı | PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute phpbb · mutant | Yüksek7,5 | — | %2,3 | 11 Nis 2007 |
31İzleyin | CVE-2008-1565Kavram kanıtı | Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbiphpbb · pjirc module · CWE-22 | Yüksek7,5 | — | %2,3 | 31 Mar 2008 |
31İzleyin | CVE-2008-1512Kavram kanıtı | Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers phpbb · module xs · CWE-22 | Yüksek7,5 | — | %2,3 | 25 Mar 2008 |
31İzleyin | CVE-2002-2287Kavram kanıtı | PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to exphpbb · advanced quick reply hack · CWE-94 | Yüksek7,5 | — | %2,3 | 31 Ara 2002 |
31İzleyin | CVE-2006-5312Kavram kanıtı | PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to ephpbb · ajax shoutbox | Yüksek7,5 | — | %2,2 | 17 Eki 2006 |
31İzleyin | CVE-2019-9826İstismar yok | The fulltext search component in phpBB before 3.2.6 allows Denial of Service.phpbb · phpbb · CWE-20 | Yüksek7,5 | — | %2,0 | 2 May 2019 |
30İzleyin | CVE-2018-19274İstismar yok | Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phaphpbb · phpbb · CWE-502 | Yüksek7,2 | — | %5,2 | 17 Kas 2018 |
30İzleyin | CVE-2017-1000419İstismar yok | phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting phpbb · phpbb · CWE-918 | Yüksek7,5 | — | %1,3 | 2 Oca 2018 |
30İzleyin | CVE-2010-1630İstismar yok | Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in cphpbb · phpbb | Yüksek7,5 | — | %1,2 | 19 May 2010 |
30İzleyin | CVE-2019-16108İstismar yok | phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.phpbb · phpbb · CWE-94 | Yüksek7,5 | — | %1,1 | 19 Mar 2020 |
30İzleyin | CVE-2003-1530Kavram kanıtı | SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the markphpbb · phpbb · CWE-89 | Yüksek7,5 | — | %1,1 | 31 Ara 2003 |
30İzleyin | CVE-2007-4653Kavram kanıtı | SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute phpbb · phpbb · CWE-89 | Yüksek7,5 | — | %1,0 | 4 Eyl 2007 |
- CVE-2006-714841Planlayın
PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to e
KritikCVSS 10,0Kavram kanıtıEPSS %3phpbb · maluinfo7 Mar 2007
- CVE-2006-717441Planlayın
PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitr
KritikCVSS 10,0İstismar yokEPSS %2phpbb · dimension21 Mar 2007
- CVE-2008-176640Planlayın
Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bu
KritikCVSS 10,0İstismar yokEPSS %1phpbb · phpbb12 Nis 2008
- CVE-2008-322440Planlayın
Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used wi
KritikCVSS 10,0İstismar yokEPSS %1phpbb · phpbb18 Tem 2008
- CVE-2007-393538İzleyin
PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary
KritikCVSS 9,3Kavram kanıtıEPSS %4phpbb · supanav20 Tem 2007
- CVE-2001-147137İzleyin
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr
YüksekCVSS 8,8Kavram kanıtıEPSS %8phpbb · phpbb31 Tem 2001
- CVE-2019-1699335İzleyin
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration C
YüksekCVSS 8,8İstismar yokEPSS %1phpbb · phpbb30 Eyl 2019
- CVE-2025-7081035İzleyin
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function an
YüksekCVSS 8,8İstismar yokEPSS %0phpbb · phpbb9 Nis 2026
- CVE-2006-716832İzleyin
PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %7phpbb · phpbb20 Mar 2007
- CVE-2026-2919932İzleyin
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning.
YüksekCVSS 8,1İstismar yokEPSS %0phpbb · phpbb4 May 2026
- CVE-2007-076131İzleyin
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrar
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpbb · ezboard converter5 Şub 2007
- CVE-2006-530931İzleyin
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for ph
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpbb · prillian french17 Eki 2006
- CVE-2006-659331İzleyin
PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP co
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb · amazonia mod15 Ara 2006
- CVE-2007-196131İzleyin
PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb · mutant11 Nis 2007
- CVE-2008-156531İzleyin
Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbi
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb · pjirc module31 Mar 2008
- CVE-2008-151231İzleyin
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb · module xs25 Mar 2008
- CVE-2002-228731İzleyin
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to ex
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb · advanced quick reply hack31 Ara 2002
- CVE-2006-531231İzleyin
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to e
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb · ajax shoutbox17 Eki 2006
- CVE-2019-982631İzleyin
The fulltext search component in phpBB before 3.2.6 allows Denial of Service.
YüksekCVSS 7,5İstismar yokEPSS %2phpbb · phpbb2 May 2019
- CVE-2018-1927430İzleyin
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Pha
YüksekCVSS 7,2İstismar yokEPSS %5phpbb · phpbb17 Kas 2018
- CVE-2017-100041930İzleyin
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting
YüksekCVSS 7,5İstismar yokEPSS %1phpbb · phpbb2 Oca 2018
- CVE-2010-163030İzleyin
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in c
YüksekCVSS 7,5İstismar yokEPSS %1phpbb · phpbb19 May 2010
- CVE-2019-1610830İzleyin
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
YüksekCVSS 7,5İstismar yokEPSS %1phpbb · phpbb19 Mar 2020
- CVE-2003-153030İzleyin
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpbb · phpbb31 Ara 2003
- CVE-2007-465330İzleyin
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpbb · phpbb4 Eyl 2007