Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Phpbb HIGH 8.8
CVE-2025-70810

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the aut…

No fix yet
Fix from $1,950 2026-04-09
Phpbb MEDIUM 6.5
CVE-2020-5502

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

Mitigation only
Fix from $1,600 2020-01-15
Phpbb MEDIUM 6.5
CVE-2019-13376

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token…

No fix yet
Fix from $1,600 2019-09-27
Phpbb HIGH 7.5
CVE-2017-1000419

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal …

No fix yet
Fix from $1,950 2018-01-02
Phpbb MEDIUM 6.8
CVE-2008-7143

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to …

Mitigation only
Fix from $1,600 2009-09-01
Phpbb MEDIUM 5.0
CVE-2008-6507

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password …

No fix yet
Fix from $1,600 2009-03-23
Phpbb MEDIUM 5.0
CVE-2008-4125

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially s…

Mitigation only
Fix from $1,600 2008-09-18
Module Xs HIGH 7.5
CVE-2008-1512

Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to includ…

No fix yet
Fix from $1,950 2008-03-25
123 Flash Chat Module MEDIUM 6.8
CVE-2008-1171

Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a …

Mitigation only
Fix from $1,600 2008-03-05
Garage HIGH 7.5
CVE-2007-6223

SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id param…

No fix yet
Fix from $1,950 2007-12-04
Supanav HIGH 9.3
CVE-2007-3935

PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2007-07-21
Ip Tracking MEDIUM 6.5
CVE-2007-2858

SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execu…

Mitigation only
Fix from $1,600 2007-05-24
Mutant HIGH 7.5
CVE-2007-1961

PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,950 2007-04-11
Dimension HIGH 10.0
CVE-2006-7174

PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP c…

Mitigation only
Fix from $1,950 2007-03-21
Phpbb HIGH 7.5
CVE-2006-7168EPSS 7%

PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2007-03-20
Maluinfo HIGH 10.0
CVE-2006-7148

PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2007-03-07
Import Tools MEDIUM 6.8
CVE-2006-7147

PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to exe…

No fix yet
Fix from $1,600 2007-03-07
Phpbb MEDIUM 5.0
CVE-2006-2220

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive…

Mitigation only
Fix from $1,600 2007-02-08
Ezboard Converter HIGH 7.5
CVE-2007-0761

PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP cod…

No fix yet
Fix from $1,950 2007-02-06
Amazonia Mod HIGH 7.5
CVE-2006-6593

PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a …

Mitigation only
Fix from $1,950 2006-12-15
Toplist MEDIUM 6.8
CVE-2006-6459

Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the…

Mitigation only
Fix from $1,600 2006-12-11
Searchindexer MEDIUM 6.8
CVE-2006-5418EPSS 6%

PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB all…

No fix yet
Fix from $1,600 2006-10-20
Advanced Quick Reply Hack HIGH 7.5
CVE-2002-2287

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2002-12-31
Phpbb MEDIUM 5.0
CVE-2002-2346

phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers…

Mitigation only
Fix from $1,600 2002-12-31
Phpbbmod MEDIUM 5.0
CVE-2002-2349

phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.

No fix yet
Fix from $1,600 2002-12-31