CVE-2026-48613 HIGH

CVE-2026-48613

Vendor Phpbb
Product phpBB
Weakness CWE-89 · SQLi
Published June 12, 2026
Last update June 12, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L/CR:H/IR:H/AR:H

What the vulnerability does

01Description

SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.

Key dates

02Disclosure timeline

June 12, 2026 CVE published
June 12, 2026 Record updated