phpBB CVE Vulnerabilities & CVE List (63)

Products (CPE): — CVEs: 63

phpBB vulnerability overview

Aggregates CVE and security vulnerability intelligence across all phpBB-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk ssrf and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 6163 of 63 CVEs
«« First « Prev Page 4 / 4 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2002-2287 PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. [email protected] 7.5 2.25% 2002-12-31 2026-04-16
CVE-2002-2255 Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode. [email protected] 4.3 1.44% 2002-12-31 2026-04-16
CVE-2001-1471 prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement. [email protected] 8.8 7.70% 2001-07-31 2026-04-16
«« First « Prev Page 4 / 4 Next »
cvelogic Threat Intelligence