CVE-2025-70811: CSRF
Published Apr 9, 2026
·Updated
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.
Affected Software
2 affected components
phpBB phpBB 3=3.3.15
phpBB phpbb=3.3.15
Event History
Apr 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70811?
CVE-2025-70811 has a medium severity due to its potential to allow unauthorized command execution.
2
How do I fix CVE-2025-70811?
To fix CVE-2025-70811, upgrade Phpbb to version 3.3.16 or later which addresses this vulnerability.
3
What type of vulnerability is CVE-2025-70811?
CVE-2025-70811 is classified as a Cross Site Request Forgery (CSRF) vulnerability.
4
Who is affected by CVE-2025-70811?
Users of Phpbb version 3.3.15 are affected by CVE-2025-70811.
5
Can CVE-2025-70811 be exploited remotely?
CVE-2025-70811 requires a local attacker to exploit the vulnerability, as it targets the Admin Control Panel functionalities.