Software-update: phpBB 3.3.19
Versies 3.3.18 en 3.3.19 van phpBB zijn kort achterelkaar uitgekomen. Met dit programma is het mogelijk om een webforum op te zetten. PhpBB wordt onder de GPL-licentie beschikbaar gesteld en maakt gebruik van PHP en een databaseprogramma om berichten op te slaan. Naast MySQL worden ook PostgreSQL, Oracle Database, Microsoft SQL Server en SQLite als databasesoftware ondersteund. Meer informatie over deze uitgave kan op deze pagina worden gevonden. De changelog voor beide uitgaven kan hieronder worden gevonden.
We are pleased to announce the release of phpBB 3.3.19 "Bertie forgot something". Due to a mistake in our packaging, the phpBB 3.3.18 downloads did not include the security fixes announced for that release.
If you have already updated to phpBB 3.3.18, your board is missing these security fixes, and we strongly recommend updating to phpBB 3.3.19 as soon as possible.
If you have not yet updated to phpBB 3.3.18, you can skip it and update directly to phpBB 3.3.19.
Apart from the missing security fixes, phpBB 3.3.19 contains no changes beyond those announced in the phpBB 3.3.18 release.
Security Issues & HardeningReflected XSS via data passed to registration page: SECURITY-301, CVE-2026-87901Reported by aikido_security on HackerOneResend rate limiting incorrectly updating expiration time: SECURITY-298Reported by jjchuck on HackerOneAttachment comment hijacking by other users: SECURITY-300Reported by aikido_security on HackerOnePotential stored XSS for string profile fields when allowing any character: SECURITY-303Reported by vnpt_dd0c4 on HackerOneMissing permission type check when applying role based permissions: SECURITY-305Reported by drakokorian on HackerOneDisclosure of hidden or unapproved topic title when emailing topic: SECURITY-306Reported by argareksapatii on HackerOneBanned Users can email members despite ban status: SECURITY-307Reported by obsidiancladlabs on HackerOneReleasing of held private messages missing CSRF protection: SECURITY-308Reported by dogeshark on HackerOneMissing encoding of username in anti abuse header: SECURITY-309Reported by winty on HackerOneMCP topic view mixing access checks for post and topic: SECURITY-310Reported by a7mmr on HackerOneModerators with f_user_lock permission may close other user's topics: SECURITY-311Reported internallyUnauthenticated SMTP Command Injection via Contact Form: SECURITY-312Reported by m3ssap0 on HackerOneModerators can close/delete reports outside their forum permissions: SECURITY-313Reported by teamsami on HackerOneMCP make normal action for topics missing check for forum-scoped moderators: SECURITY-314Reported by a7mmr on HackerOne
Reflected XSS via data passed to registration page: SECURITY-301, CVE-2026-87901Reported by aikido_security on HackerOneResend rate limiting incorrectly updating expiration time: SECURITY-298Reported by jjchuck on HackerOneAttachment comment hijacking by other users: SECURITY-300Reported by aikido_security on HackerOnePotential stored XSS for string profile fields when allowing any character: SECURITY-303Reported by vnpt_dd0c4 on HackerOneMissing permission type check when applying role based permissions: SECURITY-305Reported by drakokorian on HackerOneDisclosure of hidden or unapproved topic title when emailing topic: SECURITY-306Reported by argareksapatii on HackerOneBanned Users can email members despite ban status: SECURITY-307Reported by obsidiancladlabs on HackerOneReleasing of held private messages missing CSRF protection: SECURITY-308Reported by dogeshark on HackerOneMissing encoding of username in anti abuse header: SECURITY-309Reported by winty on HackerOneMCP topic view mixing access checks for post and topic: SECURITY-310Reported by a7mmr on HackerOneModerators with f_user_lock permission may close other user's topics: SECURITY-311Reported internallyUnauthenticated SMTP Command Injection via Contact Form: SECURITY-312Reported by m3ssap0 on HackerOneModerators can close/delete reports outside their forum permissions: SECURITY-313Reported by teamsami on HackerOneMCP make normal action for topics missing check for forum-scoped moderators: SECURITY-314Reported by a7mmr on HackerOneNotable ImprovementsAdd automatic admin notifications on security updates: PHPBB-17665Add shorter guest session time and AI bots group: PHPBB-17656
Add automatic admin notifications on security updates: PHPBB-17665Add shorter guest session time and AI bots group: PHPBB-17656Notable BugfixesIBBCode UID Throwing Deprecation Errors: PHPBB-17134
IBBCode UID Throwing Deprecation Errors: PHPBB-17134
Source:
Tweakers.net