LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2019-25685

CVE-2019-25685 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 5, 2026

phpBB - Unrestricted File Upload

Published: April 5, 2026Updated: April 5, 2026Remote Exploitable

Overview

phpBB contains an unrestricted file upload vulnerability caused by exploitation of plupload and phar:// stream wrapper in attachment settings, letting authenticated attackers execute arbitrary code via crafted zip files.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Authenticated attackers can upload malicious files leading to remote code execution and full system compromise.

Mitigation

Update to the latest phpBB version with the vulnerability fixed.

Details

CVE ID
CVE-2019-25685
Severity
High
CVSS Score
8.8
Type
unrestricted_file_upload
Status
new

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H