Vulnerabilities > Phpbb > Phpbb > 1.4.0

DATE CVE VULNERABILITY TITLE RISK
2023-11-02 CVE-2023-5917 Cross-site Scripting vulnerability in PHPbb
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10.
network
low complexity
phpbb CWE-79
6.1
2001-07-31 CVE-2001-1471 Improper Initialization vulnerability in PHPbb 1.4.0
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
network
low complexity
phpbb CWE-665
8.8