Vulnerabilidades en phpBB
5 resultadosAnálisis Vexday
phpBB apresenta 5 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, incluindo 1 crítica (CVSS ≥ 9.0), predominantemente relacionadas a controle de acesso (CWE-284). Nenhuma vulnerabilidade está sob exploração ativa confirmada (KEV), mas a recência total do portfolio de risco e a natureza das falhas de autenticação/autorização exigem avaliação urgente de patch management.
CVE-2026-48611CRITICALImproper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to uEPSS 3.9%CVE-2026-47366HIGHImproper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticatEPSS 0.3%CVE-2026-29199HIGHphpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabledEPSS 0.2%CVE-2026-48613HIGHSQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, EPSS 0.2%CVE-2026-48612HIGHImproper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s aEPSS 0.1%