phpbb CVE Vulnerabilities & Metrics

Focus on phpbb vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About phpbb Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with phpbb. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total phpbb CVEs: 16
Earliest CVE date: 31 Jul 2001, 04:00 UTC
Latest CVE date: 02 Nov 2023, 11:15 UTC

Latest CVE reference: CVE-2023-5917

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical phpbb CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.3

Max CVSS: 10.0

Critical CVEs (≥9): 5

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 37
7.0-8.9 12
9.0-10.0 5

CVSS Distribution Chart

Top 5 Highest CVSS phpbb CVEs

These are the five CVEs with the highest CVSS scores for phpbb, sorted by severity first and recency.

All CVEs for phpbb

CVE-2023-5917 phpbb vulnerability CVSS: 3.3 02 Nov 2023, 11:15 UTC

A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of the component Smiley Pack Handler. The manipulation of the argument pak leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.3.11 is able to address this issue. The patch is named ccf6e6c255d38692d72fcb613b113e6eaa240aac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244307.

CVE-2020-8226 phpbb vulnerability CVSS: 5.0 17 Aug 2020, 16:15 UTC

A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.

CVE-2019-16108 phpbb vulnerability CVSS: 5.0 20 Mar 2020, 00:17 UTC

phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

CVE-2019-16107 phpbb vulnerability CVSS: 4.3 11 Mar 2020, 13:15 UTC

Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.

CVE-2020-5502 phpbb vulnerability CVSS: 4.3 15 Jan 2020, 00:15 UTC

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

CVE-2020-5501 phpbb vulnerability CVSS: 4.3 15 Jan 2020, 00:15 UTC

phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.

CVE-2011-0544 phpbb vulnerability CVSS: 4.3 14 Nov 2019, 00:15 UTC

phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

CVE-2019-16993 phpbb vulnerability CVSS: 6.8 30 Sep 2019, 12:15 UTC

In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.

CVE-2019-13376 phpbb vulnerability CVSS: 4.3 27 Sep 2019, 13:15 UTC

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

CVE-2019-11767 phpbb vulnerability CVSS: 5.0 05 May 2019, 06:29 UTC

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.

CVE-2019-9826 phpbb vulnerability CVSS: 5.0 02 May 2019, 21:29 UTC

The fulltext search component in phpBB before 3.2.6 allows Denial of Service.

CVE-2018-19274 phpbb vulnerability CVSS: 6.5 17 Nov 2018, 13:29 UTC

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.

CVE-2017-1000419 phpbb vulnerability CVSS: 5.0 02 Jan 2018, 19:29 UTC

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

CVE-2015-3880 phpbb vulnerability CVSS: 5.8 19 Sep 2017, 15:29 UTC

Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2015-1432 phpbb vulnerability CVSS: 6.8 10 Feb 2015, 17:59 UTC

The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors.

CVE-2015-1431 phpbb vulnerability CVSS: 4.3 10 Feb 2015, 17:59 UTC

Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."

CVE-2010-1630 phpbb vulnerability CVSS: 7.5 19 May 2010, 22:30 UTC

Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."

CVE-2010-1627 phpbb vulnerability CVSS: 4.3 19 May 2010, 22:30 UTC

feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.

CVE-2008-7143 phpbb vulnerability CVSS: 6.8 01 Sep 2009, 16:30 UTC

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.

CVE-2008-6507 phpbb vulnerability CVSS: 5.0 23 Mar 2009, 16:30 UTC

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.

CVE-2008-6506 phpbb vulnerability CVSS: 5.0 23 Mar 2009, 16:30 UTC

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

CVE-2008-4125 phpbb vulnerability CVSS: 5.0 18 Sep 2008, 17:59 UTC

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.

CVE-2008-3224 phpbb vulnerability CVSS: 10.0 18 Jul 2008, 16:41 UTC

Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()."

CVE-2008-1766 phpbb vulnerability CVSS: 10.0 12 Apr 2008, 20:05 UTC

Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."

CVE-2008-1565 phpbb vulnerability CVSS: 7.5 31 Mar 2008, 22:44 UTC

Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.

CVE-2008-1512 phpbb vulnerability CVSS: 7.5 25 Mar 2008, 23:44 UTC

Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.

CVE-2008-1171 phpbb vulnerability CVSS: 6.8 05 Mar 2008, 23:44 UTC

Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php. NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs

CVE-2008-0471 phpbb vulnerability CVSS: 4.3 29 Jan 2008, 20:00 UTC

Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.

CVE-2007-6223 phpbb vulnerability CVSS: 7.5 04 Dec 2007, 17:46 UTC

SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.

CVE-2007-5688 phpbb vulnerability CVSS: 7.5 29 Oct 2007, 19:46 UTC

Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters.

CVE-2007-5173 phpbb vulnerability CVSS: 6.8 03 Oct 2007, 14:17 UTC

PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter.

CVE-2007-5100 phpbb vulnerability CVSS: 6.8 26 Sep 2007, 22:17 UTC

Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a before 20070922, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) language/lang_german/lang_admin_album.php, (2) language/lang_english/lang_main_album.php, and (3) language/lang_english/lang_admin_album.php, different vectors than CVE-2007-5009.

CVE-2007-4653 phpbb vulnerability CVSS: 7.5 04 Sep 2007, 22:17 UTC

SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.

CVE-2007-3935 phpbb vulnerability CVSS: 9.3 21 Jul 2007, 00:30 UTC

PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2007-2858 phpbb vulnerability CVSS: 6.5 24 May 2007, 19:30 UTC

SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field.

CVE-2007-1961 phpbb vulnerability CVSS: 7.5 11 Apr 2007, 10:19 UTC

PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-7174 phpbb vulnerability CVSS: 10.0 21 Mar 2007, 21:19 UTC

PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this may be the same issue as CVE-2006-5235.

CVE-2006-7168 phpbb vulnerability CVSS: 7.5 20 Mar 2007, 10:19 UTC

PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-7148 phpbb vulnerability CVSS: 10.0 07 Mar 2007, 20:19 UTC

PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. NOTE: this might be the same issues as CVE-2006-4893.

CVE-2006-7147 phpbb vulnerability CVSS: 6.8 07 Mar 2007, 20:19 UTC

PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-2220 phpbb vulnerability CVSS: 5.0 08 Feb 2007, 17:28 UTC

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.

CVE-2007-0761 phpbb vulnerability CVSS: 7.5 06 Feb 2007, 02:28 UTC

PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.

CVE-2006-6593 phpbb vulnerability CVSS: 7.5 15 Dec 2006, 19:28 UTC

PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-6459 phpbb vulnerability CVSS: 6.8 11 Dec 2006, 17:28 UTC

Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the (1) Name and (2) Information fields when adding a new site (toplistnew action).

CVE-2006-5418 phpbb vulnerability CVSS: 6.8 20 Oct 2006, 14:07 UTC

PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-5390 phpbb vulnerability CVSS: 6.8 18 Oct 2006, 19:07 UTC

PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-5301 phpbb vulnerability CVSS: 6.8 17 Oct 2006, 15:07 UTC

PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2006-5306 phpbb vulnerability CVSS: 6.8 17 Oct 2006, 15:07 UTC

Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php.

CVE-2006-5191 phpbb vulnerability CVSS: 5.1 10 Oct 2006, 04:06 UTC

PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

CVE-2003-1530 phpbb vulnerability CVSS: 7.5 31 Dec 2003, 05:00 UTC

SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

CVE-2002-2287 phpbb vulnerability CVSS: 7.5 31 Dec 2002, 05:00 UTC

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVE-2002-2346 phpbb vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.

CVE-2002-2349 phpbb vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.

CVE-2002-2255 phpbb vulnerability CVSS: 4.3 31 Dec 2002, 05:00 UTC

Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.

CVE-2001-1471 phpbb vulnerability CVSS: 4.6 31 Jul 2001, 04:00 UTC

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.