phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
In phpBB before 3.1.7-PL1, includes/acp/acpbbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a .. (dot dot) in the lien2 parameter.
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) adminboard.php, the (2) Group name and (3) Group description fields in (b) admingroups.php and (c) groupcp.php, the (4) Theme Name field in (d) adminstyles.php, and the (5) Rank Title field in (e) adminranks.php. NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603.