Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Punbb

First CVE: Apr 8, 2005Active for: 21 yearsTotal CVEs: 47
38.9
VTI Score
Medium

Punbb is a lightweight, open-source forum software platform whose vulnerability footprint, while modest in product scope, recurs across its core application and integrated private-messaging system. The exposure centers on web-application input-handling and state-management weaknesses including cross-site scripting, SQL injection, path traversal, and cross-site request forgery, which are characteristic of server-side forum logic and user-interaction layers. Public exploit code has frequently become available for Punbb vulnerabilities, reflecting both the accessibility of forum software to security researchers and the appeal of web-application flaws to the broader attacker community. Defenders deploying or maintaining instances should prioritize input validation patches and treat this vendor's disclosures as carrying meaningful attack-surface risk despite the software's narrow footprint; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
47
Total CVEs
More Total CVEs than 98% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Punbb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2005
21 years ago
Most Recent CVE
Oct 2, 2011
5,409 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-1090HIGH
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.
Mar 9, 20067.830NOYES
CVE-2005-3518HIGH
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.
Nov 6, 20057.529NOYES
CVE-2005-0569HIGH
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feat
May 2, 20057.529NOYES
CVE-2009-2787MEDIUM
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and ma
Aug 17, 20096.828NOYES
CVE-2009-2786HIGH
SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the
Aug 17, 20097.528NOYES
CVE-2009-2308HIGH
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL comm
Jul 2, 20097.528NOYES
CVE-2009-2276HIGH
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out paramete
Jul 1, 20097.528NOYES
CVE-2008-3335HIGH
Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.
Jul 27, 200810.027NONO
CVE-2005-1051MEDIUM
SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.
May 2, 20056.526NOYES
CVE-2006-5735HIGH
Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in
Nov 6, 20067.525NONO
View all 47 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products47 CVEs
68%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (2.1%)
Unknown46 (97.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (2.1%)
High0 (0.0%)
Unknown46 (97.9%)
User Interaction
None1 (2.1%)
Unknown46 (97.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (2.1%)
None0 (0.0%)
Unknown46 (97.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
27.7% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Punbb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Punbb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Punbb's Products

View all 2 CNAs →

Top CWEs