Phpbb Group maintains a family of community forum and discussion-board software, including phpBB itself and associated extensions such as auction modules, guestbooks, and toplists, which collectively enjoy broad deployment across self-hosted web communities. The vendor's disclosures center on application-layer security issues inherent to web-facing user-generated content and plugin ecosystems: code injection, input validation, path traversal, and cross-site scripting vulnerabilities recur across the product line and reflect the challenges of sanitizing and controlling user input and dynamically loaded code in forum environments. Public exploit code frequently accompanies disclosures affecting these products, consistent with the accessibility of public forum instances and the appeal of forum takeover and defacement as common attack vectors. The exposure is concentrated in phpBB's core and its community-contributed extensions rather than spread across a large product portfolio, making targeted patching and plugin audits the primary defensive measures. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpbb Group over time
Signals from CVEs in this vendor scope (165 CVEs).
165 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2086HIGH PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code. | Jul 5, 2005 | 7.5 | 83 | NO | YES |
CVE-2004-1315HIGH viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arb | Nov 12, 2004 | 7.5 | 79 | NO | YES |
CVE-2026-48611CRITICAL Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installati | Jun 12, 2026 | 9.8 | 54 | NO | YES |
CVE-2001-1471HIGH prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock i | Jul 31, 2001 | 8.8 | 41 | NO | YES |
CVE-2004-1535HIGH PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path p | Dec 31, 2004 | 7.5 | 37 | NO | YES |
CVE-2005-1193HIGH The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to exe | May 16, 2005 | 7.5 | 36 | NO | YES |
CVE-2006-7148HIGH PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_ | Mar 7, 2007 | 10.0 | 35 | NO | YES |
CVE-2002-2176HIGH SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page. | Dec 31, 2002 | 10.0 | 35 | NO | YES |
CVE-2007-3935HIGH PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_pat | Jul 21, 2007 | 9.3 | 34 | NO | YES |
CVE-2004-2350HIGH SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter. | Dec 31, 2004 | 7.5 | 34 | NO | YES |
Signals from CVEs in this vendor scope (165 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpbb Group.
Media articles that mention a CVE ID that affects a product developed by Phpbb Group — matched by CVE ID, not by vendor name.