PhpBB Program Statistics
5 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — Cross-site Scripting (XSS) - Stored
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| Stored XSS via SVG Upload — check_content() Blocklist Bypass & 256-Byte Scan Limit (Self-Propagating Worm) | Cross-site Scripting (XSS) - Stored | a7mmr | Medium | 2026-07-30 |
| Blind POST SSRF via Web Push Notification Endpoint | Server-Side Request Forgery (SSRF) | misop00p | Medium | 2026-05-30 |
| Authenticated path traversal to Stored XSS and Denial-of-Service | Cross-site Scripting (XSS) - Stored | shin24 | No rating | 2023-10-29 |
| Server Side Request Forgery in 'Jabber settings' in Admin Control Panel | Server-Side Request Forgery (SSRF) | they | Low | 2020-12-20 |
| CSS injection via BB code tag "█████" | Resource Injection | hanno | Medium | 2019-09-26 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles