Phpbb

Vendor:

First CVE: Jul 31, 2001 · Active for 24 years

130
Total CVEs
More Total CVEs than 97% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Phpbb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2001
24 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

CVE Severity & Scoring

Phpbb130 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (16.9%)
Unknown108 (83.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (15.4%)
High2 (1.5%)
Unknown108 (83.1%)
User Interaction
None9 (6.9%)
Unknown108 (83.1%)
Required13 (10.0%)
Privileges Required
Low3 (2.3%)
High2 (1.5%)
None17 (13.1%)
Unknown108 (83.1%)

Top CVEs

Signals from CVEs in this product scope (130 CVEs).

130 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
Jul 5, 20057.583NOYES
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arb
Nov 12, 20047.579NOYES
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installati
Jun 12, 20269.854NOYES
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock i
Jul 31, 20018.841NOYES
PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path p
Dec 31, 20047.537NOYES
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to exe
May 16, 20057.536NOYES
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.
Dec 31, 200210.035NOYES
SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter.
Dec 31, 20047.534NOYES
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.
Dec 31, 20037.534NOYES
PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_pat
Mar 20, 20077.533NOYES

Exploit Exposure

Signals from CVEs in this product scope (130 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.5% of CVEs· Bottom 1%
Nuclei
1 CVE
0.8% of CVEs· 96th percentile
ExploitDB
37 CVEs
28.5% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (130 CVEs).

Media Mentions

Signals from CVEs in this product scope (130 CVEs).

Top CNAs Publishing CVEs For Phpbb

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
rc417.56.3%01
rc317.56.3%01
rc217.56.3%01
rc1_pre17.56.3%01
rc117.56.3%01
build_10017.53.3%01
3.3.1526.50.2%00
3.2.825.40.4%00
3.2.736.10.7%00
3.2.017.51.3%00
3.1.416.12.1%00
3.1.316.12.1%00
3.1.216.12.1%00
3.1.116.12.1%00
3.1.016.12.1%00
3.0.714.31.1%00
3.0.326.31.2%00
3.0.235.81.2%00
3.0.135.81.2%00
3.0.0rc110.01.5%00