CVE-2019-25685: phpBB Arbitrary File Upload via Phar Deserialization
Published Apr 5, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
phpBB phpbb<=3.2.3
Event History
Apr 5, 2026
CVE Published
via MITRE·08:45 PM
Rejected
via MITRE·08:45 PM
Data Sourced
via NVD·09:16 PM
Description
Apr 19, 2026
Rejected
via MITRE·12:36 PM
Frequently Asked Questions
1
What does CVE-2019-25685 refer to?
CVE-2019-25685 refers to a rejected CVE related to an arbitrary file upload vulnerability in phpBB via Phar deserialization.
2
Which versions of phpBB are affected by CVE-2019-25685?
CVE-2019-25685 impacts phpBB versions up to and including 3.2.3.
3
Is there a fix available for CVE-2019-25685?
Since CVE-2019-25685 has been rejected, no fix is applicable.
4
What should I do if I am using an affected version of phpBB?
If using an affected version of phpBB, it is recommended to upgrade to a secure and supported version.
5
How can I verify if my phpBB installation is vulnerable to CVE-2019-25685?
As CVE-2019-25685 is a rejected CVE, it is important to check other related vulnerabilities for accurate assessments.