Phpbb Group

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 93
    Known Exploited: 0
    7
    Critical Level Threats
    28
    High Level Threats
    56
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-1695

    PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly

    Last Modified: Apr 23, 2026
    Published: Mar 27, 2007

    CVE-2006-7076

    Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.

    Last Modified: Apr 23, 2026
    Published: Feb 27, 2007

    CVE-2006-7077

    SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.

    Last Modified: Apr 23, 2026
    Published: Feb 27, 2007

    CVE-2006-2219

    phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.

    Last Modified: Apr 23, 2026
    Published: Feb 08, 2007

    CVE-2006-6839

    Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."

    Last Modified: Apr 23, 2026
    Published: Dec 31, 2006
    Items Per Page
    Phpbb_Group Vulnerabilities & Security CVEs | CVE-DB