Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpbb
Phpbb phpbb |
|
| CPEs | cpe:2.3:a:phpbb:phpbb:3.3.15:-:*:*:*:*:*:* | |
| Vendors & Products |
Phpbb
Phpbb phpbb |
Wed, 15 Apr 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSRF in phpBB Icon Management Enables Local Administrative Code Execution |
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSRF in phpBB 3.3.15 Admin Icon Management Enables Local Code Execution | |
| Weaknesses | CWE-94 |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 10 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSRF in phpBB 3.3.15 Admin Icon Management Enables Local Code Execution | |
| Weaknesses | CWE-352 CWE-94 |
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ariefibis
Ariefibis phpbb3 |
|
| Vendors & Products |
Ariefibis
Ariefibis phpbb3 |
Thu, 09 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T16:35:34.486Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70811
Updated: 2026-04-14T14:46:02.252Z
Status : Analyzed
Published: 2026-04-09T15:16:09.163
Modified: 2026-04-17T13:05:33.037
Link: CVE-2025-70811
No data.
OpenCVE Enrichment
Updated: 2026-04-15T22:45:16Z