Phorum is a web-based forum and discussion platform that, despite its narrow product scope, occupies a prominent position in the vulnerability landscape reflecting its historical ubiquity in community-driven websites and content platforms. The vendor's disclosure pattern centers on application-layer input-handling and session-management weaknesses including cross-site scripting, SQL injection, cross-site request forgery, and sensitive information exposure that are characteristic of server-side web applications handling user-contributed content and authentication. A notable tendency toward public exploit availability reflects the appeal of forum platforms as targets for defacement, account compromise, and privilege escalation, particularly across instances running legacy or unpatched versions. Defenders tracking Phorum installations should prioritize input sanitization, parameterized queries, and session hardening; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phorum over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0764HIGH Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] vari | Aug 12, 2002 | 7.5 | 48 | NO | YES |
CVE-2007-2338HIGH Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an adminis | Apr 27, 2007 | 7.5 | 32 | NO | YES |
CVE-2006-3053HIGH PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] paramete | Jun 16, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-2339HIGH Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; | Apr 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-2249MEDIUM include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array. | Apr 25, 2007 | 6.5 | 28 | NO | YES |
CVE-2006-6550HIGH PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: | Dec 14, 2006 | 7.5 | 28 | NO | YES |
CVE-2004-1938HIGH SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is t | Apr 19, 2004 | 7.5 | 28 | NO | YES |
CVE-2003-1487HIGH Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) | Dec 31, 2003 | 10.0 | 28 | NO | NO |
CVE-2003-0283MEDIUM Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in | Jun 16, 2003 | 6.8 | 28 | NO | YES |
CVE-2012-4234MEDIUM Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web | Sep 4, 2014 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phorum.
Media articles that mention a CVE ID that affects a product developed by Phorum — matched by CVE ID, not by vendor name.