← Back

Phpbb

phpbb

65 CVEs • 26 products

Products (26)

Click to collapse
Toggle
Phpbb
phpbb
Phpbbmod
phpbbmod
Spamblockermod
spamblockermod
Lat2cyr
lat2cyr
Ajax Shoutbox
ajax_shoutbox
Searchindexer
searchindexer
Toplist
toplist
Amazonia Mod
amazonia_mod
Insert User
insert_user
Import Tools
import_tools
Maluinfo
maluinfo
Dimension
dimension
Mutant
mutant
Ip Tracking
ip-tracking
Supanav
supanav
Phpbb Plus
phpbb_plus
Garage
garage
Module Xs
module_xs
Pjirc Module
pjirc_module
Tag Board
tag_board

CVEs (65)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpbb
1Phpbbmod
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.
1Phpbb
1Phpbb
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.
1Phpbb
1Advanced Quick Reply Hack
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.
1Phpbb
1Phpbb
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.
1Phpbb
1Phpbb
Apr 16, 2026
Jul 31, 2001
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth...Show more
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.Show less