Products: 26
    Vulnerabilities: 72
    Known Exploited: 0
    6
    Critical Level Threats
    29
    High Level Threats
    35
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48613

    SQL Injection in phpBB Profile Field Migration Allowing Arbitrary SQL Execution

    Last Modified: Jun 12, 2026
    Published: Jun 12, 2026

    CVE-2026-48612

    Improper OAuth State Verification Allows Account Takeover

    Last Modified: Jun 12, 2026
    Published: Jun 12, 2026

    CVE-2026-47366

    Privilege Escalation via Improper Permission Verification in phpBB ACP

    Last Modified: Jun 12, 2026
    Published: Jun 12, 2026

    CVE-2026-48611

    OAuth Authentication Bypass Allows Account Hijacking in phpBB

    Last Modified: Jul 31, 2026
    Published: Jun 12, 2026

    CVE-2026-29199

    phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover.

    Last Modified: May 29, 2026
    Published: May 04, 2026
    Items Per Page
    Phpbb Vulnerabilities & Security CVEs | CVE-DB