📦

phpbb

Vendor: phpbb

Actively Exploited 0 CISA KEV List
PoC / Exploits 36 Code Available
Total RCEs 8 Remote Access
Total CVEs 544 Total Indexed
Avg. EPSS 3.43% Exploit Prob.
Latest CVE CVE-2026-29199 May 04

Security Vulnerability Index

Page 13 / 55
5.1 CVSS

Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.

EPSS: 1.33%
5.0 CVSS

phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.

EPSS: 1.80%
10.0 CVSS

db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.

EPSS: 5.27%
7.5 CVSS

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

EPSS: 1.23%
4.6 CVSS
CVE-2001-1472
Exploit Found

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

EPSS: 2.58%
8.8 CVSS
CVE-2001-1471
Exploit Found

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

EPSS: 7.70%