CVE-2026-29199
- EPSS 0.03%
- Veröffentlicht 04.05.2026 05:42:15
- Zuletzt bearbeitet 07.05.2026 15:53:49
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset...
CVE-2025-70811
- EPSS 0.02%
- Veröffentlicht 09.04.2026 00:00:00
- Zuletzt bearbeitet 17.04.2026 13:05:33
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.
CVE-2025-70810
- EPSS 0.1%
- Veröffentlicht 09.04.2026 00:00:00
- Zuletzt bearbeitet 17.04.2026 13:06:33
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism
CVE-2019-25685
- EPSS 0.18%
- Veröffentlicht 05.04.2026 20:45:33
- Zuletzt bearbeitet 19.04.2026 13:16:33
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-5917
- EPSS 0.1%
- Veröffentlicht 02.11.2023 11:15:14
- Zuletzt bearbeitet 21.11.2024 08:42:46
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of the component Smiley Pack Handler. The manipulation of the argument pak l...
CVE-2020-8226
- EPSS 0.18%
- Veröffentlicht 17.08.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:32
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
CVE-2019-16108
- EPSS 0.25%
- Veröffentlicht 20.03.2020 00:17:09
- Zuletzt bearbeitet 21.11.2024 04:30:03
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
CVE-2019-16107
- EPSS 0.09%
- Veröffentlicht 11.03.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:03
Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
CVE-2020-5501
- EPSS 0.1%
- Veröffentlicht 15.01.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 05:34:10
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
CVE-2020-5502
- EPSS 0.1%
- Veröffentlicht 15.01.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 05:34:10
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.