📦

phpbb

Vendor: phpbb

Actively Exploited 0 CISA KEV List
PoC / Exploits 36 Code Available
Total RCEs 8 Remote Access
Total CVEs 544 Total Indexed
Avg. EPSS 3.43% Exploit Prob.
Latest CVE CVE-2026-29199 May 04

Security Vulnerability Index

Page 5 / 55
5.0 CVSS

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.

EPSS: 1.46%
10.0 CVSS

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."

EPSS: 1.57%
10.0 CVSS

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."

EPSS: 1.57%
10.0 CVSS

Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

EPSS: 1.57%
6.0 CVSS

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: 1.02%
6.0 CVSS
CVE-2006-6421
Exploit Found

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

EPSS: 15.45%
7.5 CVSS

PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: CVE and the vendor dispute this vulnerability because $phpbb_root_path is defined before use

EPSS: 1.26%
5.1 CVSS
CVE-2006-5191
RCE Exploit Found

PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

EPSS: 3.14%
7.5 CVSS
CVE-2006-5209
Exploit Found

PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

EPSS: 2.28%
4.6 CVSS

phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.

EPSS: 1.58%