phpBB CVE Vulnerabilities & CVE List (92)

Products (CPE): — CVEs: 92

phpBB vulnerability overview

Aggregates CVE and security vulnerability intelligence across all phpBB-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting, vendor risk path handling, and vendor risk input validation; exposure may include vendor impact file overwrite in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 2140 of 92 CVEs
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2006-2151 PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. [email protected] 7.5 17.35% 2006-05-03 2026-04-16
CVE-2006-2150 PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter. [email protected] 6.4 0.36% 2006-05-03 2026-04-16
CVE-2006-2134 PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. [email protected] 5.1 6.32% 2006-05-02 2026-04-16
CVE-2006-1896 Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability. [email protected] 6.0 1.27% 2006-04-20 2026-04-16
CVE-2006-1895 Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl. [email protected] 6.5 0.36% 2006-04-20 2026-04-16
CVE-2006-1775 Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php. NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603. [email protected] 4.3 0.41% 2006-04-13 2026-04-16
CVE-2006-1603 Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. [email protected] 4.3 0.51% 2006-04-04 2026-04-16
CVE-2006-0632 The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts. [email protected] 6.4 0.98% 2006-02-10 2026-04-16
CVE-2006-0438 Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php. [email protected] 5.0 0.82% 2006-02-06 2026-04-16
CVE-2006-0437 Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters. [email protected] 4.3 2.61% 2006-02-06 2026-04-16
CVE-2006-0450 phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database. [email protected] 5.0 10.44% 2006-01-27 2026-04-16
CVE-2006-0063 Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357. [email protected] 4.3 0.41% 2006-01-05 2026-04-16
CVE-2005-3537 A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs. [email protected] 5.0 0.38% 2005-12-22 2026-04-16
CVE-2005-3536 SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type. [email protected] 7.5 0.50% 2005-12-22 2026-04-16
CVE-2005-4358 admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message. [email protected] 5.0 1.26% 2005-12-20 2026-04-16
CVE-2005-4357 Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover. [email protected] 2.6 1.42% 2005-12-20 2026-04-16
CVE-2005-3799 phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax or the full installation path. [email protected] 5.0 0.46% 2005-11-24 2026-04-16
CVE-2005-3420 usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement. [email protected] 7.5 2.32% 2005-11-01 2026-04-16
CVE-2005-3419 SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized. [email protected] 7.5 1.31% 2005-11-01 2026-04-16
CVE-2005-3418 Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) list_cat parameter to search.php, which are not initialized as variables. [email protected] 4.3 1.45% 2005-11-01 2026-04-16
cvelogic Threat Intelligence