Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.3% | — | Phpbb Group Phpbb | 6/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters. | |
| Modificada | Media (5) | 5.1% | — | Phpbb Group Phpbb | 27/1/2006 | 16/6/2026 | phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database. | |
| Modificada | Media (4.3) | 1.3% | — | Phpbb Group Phpbb | 5/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357. | |
| Modificada | Media (5) | 1.4% | — | Phpbb Group Phpbb | 22/12/2005 | 16/6/2026 | A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpbb Group Phpbb | 22/12/2005 | 16/6/2026 | SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type. | |
| Modificada | Baja (2.6) | 1.9% | — | Phpbb Group Phpbb | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover. | |
| Modificada | Media (5) | 2.1% | — | Phpbb Group Phpbb | 20/12/2005 | 16/6/2026 | admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message. | |
| Modificada | Media (5) | 1.3% | — | Anthony Boyd Phpbb Blog | 19/12/2005 | 16/6/2026 | Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a SQL syntax error message. NOTE: this was originally claimed to… | |
| Modificada | Media (5) | 1.5% | — | Phpbb Styles Extreme Styles Phpbb Module | 8/12/2005 | 16/6/2026 | Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter. | |
| Modificada | Media (5) | 1.2% | — | Phpbb Styles Phpbb Extreme Styles | 8/12/2005 | 16/6/2026 | xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter. | |
| Modificada | Media (5) | 1.6% | — | Phpbb Group Phpbb | 24/11/2005 | 16/6/2026 | phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax or the full installation path. | |
| Modificada | Alta (7.5) | 2.3% | — | Phpbb Group Phpbb | 1/11/2005 | 16/6/2026 | phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables. | |
| Modificada | Alta (7.5) | 2.3% | — | Phpbb Group Phpbb | 1/11/2005 | 16/6/2026 | phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote attackers to bypass security checks by setting the $_SESSION and $HTTP_SESSION_VARS variables to strings instead of arrays, which causes an array_merge function call to fail. | |
| Modificada | Media (4.3) | 1.8% | — | Phpbb Group Phpbb | 1/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) list_cat parameter to search.php, which are not initialized as variables. | |
| Modificada | Alta (7.5) | 1.9% | — | Phpbb Group Phpbb | 1/11/2005 | 16/6/2026 | SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized. | |
| Modificada | Alta (7.5) | 2.4% | — | Phpbb Group Phpbb | 1/11/2005 | 16/6/2026 | usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement. | |
| Modificada | Alta (7.5) | 2.4% | — | Phpbb Group Phpbb | 1/11/2005 | 16/6/2026 | phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable. | |
| Modificada | Baja (3.5) | 1.2% | — | Phpbb Group Phpbb | 26/10/2005 | 16/6/2026 | Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders… | |
| Modificada | Media (4.3) | 1.2% | — | Phpbb Group Phpbb | 6/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags. | |
| Modificada | Alta (7.5) | 85% | — | Phpbb Group Phpbb | 5/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code. | |
| Modificada | Alta (7.5) | 16% | — | Phpbb Group Phpbb | 16/5/2005 | 16/6/2026 | The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI… | |
| Modificada | Alta (7.5) | 1.7% | — | Oxpus Phpbb Personal Notes Module | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Phpbb Group Phpbb | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by… | |
| Modificada | Media (5) | 1.6% | — | Phpbb Group Phpbb-auction | 2/5/2005 | 16/6/2026 | auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message. | |
| Modificada | Media (5) | 1.5% | — | Phpbb Group Phpbb | 2/5/2005 | 16/6/2026 | calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message. |