Phpbb develops and maintains a widely deployed forum and community-discussion platform whose vulnerability footprint reflects the complexity of web application development at scale. The vendor's exposure concentrates in its flagship Phpbb product and related modules, with recurring weakness classes including code injection, SQL injection, cross-site scripting, and cross-site request forgery—characteristic input-handling and state-management flaws endemic to forum software. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching essential for administrators of internet-exposed instances. Defenders should treat Phpbb advisories as high-priority for community-discussion deployments and maintain inventory of affected versions; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpbb over time
Signals from CVEs in this vendor scope (165 CVEs).
165 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2086HIGH PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code. | Jul 5, 2005 | 7.5 | 83 | NO | YES |
CVE-2004-1315HIGH viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arb | Nov 12, 2004 | 7.5 | 79 | NO | YES |
CVE-2026-48611CRITICAL Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installati | Jun 12, 2026 | 9.8 | 54 | NO | YES |
CVE-2001-1471HIGH prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock i | Jul 31, 2001 | 8.8 | 41 | NO | YES |
CVE-2004-1535HIGH PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path p | Dec 31, 2004 | 7.5 | 37 | NO | YES |
CVE-2005-1193HIGH The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to exe | May 16, 2005 | 7.5 | 36 | NO | YES |
CVE-2006-7148HIGH PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_ | Mar 7, 2007 | 10.0 | 35 | NO | YES |
CVE-2002-2176HIGH SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page. | Dec 31, 2002 | 10.0 | 35 | NO | YES |
CVE-2007-3935HIGH PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_pat | Jul 21, 2007 | 9.3 | 34 | NO | YES |
CVE-2004-2350HIGH SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter. | Dec 31, 2004 | 7.5 | 34 | NO | YES |
Signals from CVEs in this vendor scope (165 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpbb.
Media articles that mention a CVE ID that affects a product developed by Phpbb — matched by CVE ID, not by vendor name.