CVE-2025-70810: CSRF
Published Apr 9, 2026
·Updated
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism
Affected Software
2 affected components
phpBB phpbb=3.3.15
phpBB phpbb=3.3.15
Event History
Apr 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70810?
CVE-2025-70810 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2025-70810?
To fix CVE-2025-70810, upgrade phpBB to version 3.3.16 or later which addresses this vulnerability.
3
What systems are affected by CVE-2025-70810?
CVE-2025-70810 specifically affects phpBB version 3.3.15.
4
What type of attack does CVE-2025-70810 facilitate?
CVE-2025-70810 facilitates Cross Site Request Forgery attacks enabling unauthorized actions on behalf of users.
5
Who can exploit CVE-2025-70810?
CVE-2025-70810 can be exploited by a local attacker who can execute arbitrary code via the login function.