Punbb is a lightweight, open-source forum software platform whose vulnerability footprint, while modest in product scope, recurs across its core application and integrated private-messaging system. The exposure centers on web-application input-handling and state-management weaknesses including cross-site scripting, SQL injection, path traversal, and cross-site request forgery, which are characteristic of server-side forum logic and user-interaction layers. Public exploit code has frequently become available for Punbb vulnerabilities, reflecting both the accessibility of forum software to security researchers and the appeal of web-application flaws to the broader attacker community. Defenders deploying or maintaining instances should prioritize input validation patches and treat this vendor's disclosures as carrying meaningful attack-surface risk despite the software's narrow footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Punbb over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1090HIGH register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations. | Mar 9, 2006 | 7.8 | 30 | NO | YES |
CVE-2005-3518HIGH SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter. | Nov 6, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-0569HIGH Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feat | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2009-2787MEDIUM Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and ma | Aug 17, 2009 | 6.8 | 28 | NO | YES |
CVE-2009-2786HIGH SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the | Aug 17, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2308HIGH Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL comm | Jul 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2276HIGH SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out paramete | Jul 1, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-3335HIGH Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors. | Jul 27, 2008 | 10.0 | 27 | NO | NO |
CVE-2005-1051MEDIUM SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action. | May 2, 2005 | 6.5 | 26 | NO | YES |
CVE-2006-5735HIGH Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in | Nov 6, 2006 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Punbb.
Media articles that mention a CVE ID that affects a product developed by Punbb — matched by CVE ID, not by vendor name.