Phpbb
Vendor:
First CVE: Jul 31, 2001 · Active for 24 years
130
Total CVEs
More Total CVEs than 97% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phpbb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2001
24 years ago
Most Recent CVE
Jun 12, 2026
42 days ago
CVE Severity & Scoring
Phpbb130 CVEs
57%
41%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (16.9%)
Unknown108 (83.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (15.4%)
High2 (1.5%)
Unknown108 (83.1%)
User Interaction
None9 (6.9%)
Unknown108 (83.1%)
Required13 (10.0%)
Privileges Required
Low3 (2.3%)
High2 (1.5%)
None17 (13.1%)
Unknown108 (83.1%)
Top CVEs
Signals from CVEs in this product scope (130 CVEs).
130 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2086HIGH PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code. | Jul 5, 2005 | 7.5 | 83 | NO | YES |
CVE-2004-1315HIGH viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arb | Nov 12, 2004 | 7.5 | 79 | NO | YES |
CVE-2026-48611CRITICAL Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installati | Jun 12, 2026 | 9.8 | 54 | NO | YES |
CVE-2001-1471HIGH prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock i | Jul 31, 2001 | 8.8 | 41 | NO | YES |
CVE-2004-1535HIGH PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path p | Dec 31, 2004 | 7.5 | 37 | NO | YES |
CVE-2005-1193HIGH The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to exe | May 16, 2005 | 7.5 | 36 | NO | YES |
CVE-2002-2176HIGH SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page. | Dec 31, 2002 | 10.0 | 35 | NO | YES |
CVE-2004-2350HIGH SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter. | Dec 31, 2004 | 7.5 | 34 | NO | YES |
CVE-2003-1530HIGH SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter. | Dec 31, 2003 | 7.5 | 34 | NO | YES |
CVE-2006-7168HIGH PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_pat | Mar 20, 2007 | 7.5 | 33 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (130 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.5% of CVEs· Bottom 1%
Nuclei
1 CVE
0.8% of CVEs· 96th percentile
ExploitDB
37 CVEs
28.5% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (130 CVEs).
Media Mentions
Signals from CVEs in this product scope (130 CVEs).
Top CNAs Publishing CVEs For Phpbb
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| rc4 | 1 | 7.5 | 6.3% | 0 | 1 |
| rc3 | 1 | 7.5 | 6.3% | 0 | 1 |
| rc2 | 1 | 7.5 | 6.3% | 0 | 1 |
| rc1_pre | 1 | 7.5 | 6.3% | 0 | 1 |
| rc1 | 1 | 7.5 | 6.3% | 0 | 1 |
| build_100 | 1 | 7.5 | 3.3% | 0 | 1 |
| 3.3.15 | 2 | 6.5 | 0.2% | 0 | 0 |
| 3.2.8 | 2 | 5.4 | 0.4% | 0 | 0 |
| 3.2.7 | 3 | 6.1 | 0.7% | 0 | 0 |
| 3.2.0 | 1 | 7.5 | 1.3% | 0 | 0 |
| 3.1.4 | 1 | 6.1 | 2.1% | 0 | 0 |
| 3.1.3 | 1 | 6.1 | 2.1% | 0 | 0 |
| 3.1.2 | 1 | 6.1 | 2.1% | 0 | 0 |
| 3.1.1 | 1 | 6.1 | 2.1% | 0 | 0 |
| 3.1.0 | 1 | 6.1 | 2.1% | 0 | 0 |
| 3.0.7 | 1 | 4.3 | 1.1% | 0 | 0 |
| 3.0.3 | 2 | 6.3 | 1.2% | 0 | 0 |
| 3.0.2 | 3 | 5.8 | 1.2% | 0 | 0 |
| 3.0.1 | 3 | 5.8 | 1.2% | 0 | 0 |
| 3.0.0rc | 1 | 10.0 | 1.5% | 0 | 0 |