📦

phpbb

Vendor: phpbb_group

Actively Exploited 0 CISA KEV List
PoC / Exploits 36 Code Available
Total RCEs 8 Remote Access
Total CVEs 170 Total Indexed
Avg. EPSS 3.43% Exploit Prob.
Latest CVE CVE-2026-29199 May 04

Security Vulnerability Index

Page 3 / 17
7.5 CVSS

Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."

EPSS: 1.23%
4.3 CVSS

feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.

EPSS: 1.11%
6.5 CVSS
CVE-2009-3052
Exploit Found

SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php.

EPSS: 0.88%
6.8 CVSS

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.

EPSS: 1.05%
5.0 CVSS

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.

EPSS: 1.10%
5.0 CVSS

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

EPSS: 1.30%
7.5 CVSS
CVE-2008-6314
Exploit Found

SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

EPSS: 1.00%
7.5 CVSS
CVE-2008-6301
Exploit Found

SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

EPSS: 0.97%
5.0 CVSS

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.

EPSS: 1.63%
10.0 CVSS

Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()."

EPSS: 1.49%