Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpbb vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2019-16108
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
Phpbb Phpbb 3.2.7
4.3
CVSSv2
CVE-2020-5501
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
Phpbb Phpbb 3.2.8
4.3
CVSSv2
CVE-2020-5502
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
Phpbb Phpbb 3.2.8
4.3
CVSSv2
CVE-2005-1116
Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote malicious users to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.
Phpbb Group Phpbb
7.5
CVSSv2
CVE-2006-5435
PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: CVE and the vendor dispute this vulnerability because $phpbb_root_path is def...
Phpbb Group Phpbb
4.3
CVSSv2
CVE-2006-2359
Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote malicious users to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
Phpbb Group Phpbb
1 EDB exploit
7.5
CVSSv2
CVE-2005-1196
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote malicious users to obtain sensitive information and execute SQL commands via the cat parameter.
Phpbb Group Phpbb
1 EDB exploit
6.8
CVSSv2
CVE-2008-7143
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote malicious users to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID i...
Phpbb Phpbb 2.0.23
5
CVSSv2
CVE-2017-1000419
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an malicious user to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
Phpbb Phpbb 3.2.0
5
CVSSv2
CVE-2005-4358
admin/admin_disallow.php in phpBB 2.0.18 allows remote malicious users to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.
Phpbb Group Phpbb 2.0.18
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »