
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48613 is a SQL injection vulnerability in phpBB's profile field migration process, caused by improper handling of user-supplied profile field data during database migration. It allows low-privileged authenticated attackers to execute arbitrary SQL queries against the affected forum database. The vulnerability exclusively affects phpBB installations that were previously upgraded from versions prior to 3.3.8 and have not yet been updated to version 3.3.11 or newer (affected range: 3.3.8–3.3.10). It was published on June 12, 2026, with a CVSS v3.0 base score of 5.9 (Medium) per NVD, though ENISA's EUVD rates it 7.1 (High) (GitHub Advisory, ENISA EUVD).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), where user-supplied profile field data is not properly sanitized or parameterized during the migration routine introduced in phpBB 3.3.8 (GitHub Advisory). An attacker with low-level privileges can manipulate profile field values that are subsequently processed by the migration logic without adequate escaping, causing the database engine to interpret the injected content as SQL commands. Exploitation requires network access, low privileges, user interaction, and high attack complexity, limiting the practical attack surface to specific migration-state forums (GitHub Advisory). No public proof-of-concept code has been identified at this time (ENISA EUVD).
Successful exploitation allows an attacker to read sensitive database contents (high confidentiality impact), modify database records (low integrity impact), and potentially disrupt database operations (low availability impact) (GitHub Advisory). Exposed data may include user credentials, private messages, email addresses, and other forum data stored in the database. The scope is limited to the affected phpBB database instance and does not extend to the underlying operating system under typical configurations (ENISA EUVD).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of publication (ENISA EUVD). The CVE status is listed as "Deferred" and no threat actor attribution has been reported. The EPSS score is approximately 0.036%–0.155%, indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity and requirement for user interaction further reduce practical exploitability.
The primary remediation is to update phpBB to version 3.3.11 or newer, which addresses the improper handling of profile field data during migration (GitHub Advisory, phpBB Community). Forums that were never upgraded from a version prior to 3.3.8, or that have already been updated to 3.3.11+, are not affected. If immediate patching is not feasible, administrators should restrict access to profile field migration functionality and limit forum administrative access to trusted users only during the upgrade window (ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."