Software-update: phpBB 3.3.19

phpBB logo Versies 3.3.18 en 3.3.19 van phpBB zijn kort achterelkaar uitgekomen. Met dit programma is het mogelijk om een webforum op te zetten. PhpBB wordt onder de GPL-licentie beschikbaar gesteld en maakt gebruik van PHP en een databaseprogramma om berichten op te slaan. Naast MySQL worden ook PostgreSQL, Oracle Database, Microsoft SQL Server en SQLite als databasesoftware ondersteund. Meer informatie over deze uitgave kan op deze pagina worden gevonden. De changelog voor beide uitgaven kan hieronder worden gevonden.

phpBB 3.3.19 Release - Urgent update

We are pleased to announce the release of phpBB 3.3.19 "Bertie forgot something". Due to a mistake in our packaging, the phpBB 3.3.18 downloads did not include the security fixes announced for that release.

If you have already updated to phpBB 3.3.18, your board is missing these security fixes, and we strongly recommend updating to phpBB 3.3.19 as soon as possible.

If you have not yet updated to phpBB 3.3.18, you can skip it and update directly to phpBB 3.3.19.

Apart from the missing security fixes, phpBB 3.3.19 contains no changes beyond those announced in the phpBB 3.3.18 release.

phpBB 3.3.18 Release - Release Highlights

Security Issues & Hardening
  • Reflected XSS via data passed to registration page: SECURITY-301, CVE-2026-87901
  • Reported by aikido_security on HackerOne
  • Resend rate limiting incorrectly updating expiration time: SECURITY-298
  • Reported by jjchuck on HackerOne
  • Attachment comment hijacking by other users: SECURITY-300
  • Reported by aikido_security on HackerOne
  • Potential stored XSS for string profile fields when allowing any character: SECURITY-303
  • Reported by vnpt_dd0c4 on HackerOne
  • Missing permission type check when applying role based permissions: SECURITY-305
  • Reported by drakokorian on HackerOne
  • Disclosure of hidden or unapproved topic title when emailing topic: SECURITY-306
  • Reported by argareksapatii on HackerOne
  • Banned Users can email members despite ban status: SECURITY-307
  • Reported by obsidiancladlabs on HackerOne
  • Releasing of held private messages missing CSRF protection: SECURITY-308
  • Reported by dogeshark on HackerOne
  • Missing encoding of username in anti abuse header: SECURITY-309
  • Reported by winty on HackerOne
  • MCP topic view mixing access checks for post and topic: SECURITY-310
  • Reported by a7mmr on HackerOne
  • Moderators with f_user_lock permission may close other user's topics: SECURITY-311
  • Reported internally
  • Unauthenticated SMTP Command Injection via Contact Form: SECURITY-312
  • Reported by m3ssap0 on HackerOne
  • Moderators can close/delete reports outside their forum permissions: SECURITY-313
  • Reported by teamsami on HackerOne
  • MCP make normal action for topics missing check for forum-scoped moderators: SECURITY-314
  • Reported by a7mmr on HackerOne
Notable Improvements
  • Add automatic admin notifications on security updates: PHPBB-17665
  • Add shorter guest session time and AI bots group: PHPBB-17656
Notable Bugfixes
phpBB 3.1 screenshot (620 pix)
Versienummer 3.3.19
Releasestatus Final
Besturingssystemen Scripttaal
Website phpBB
Download https://www.phpbb.com/downloads
Licentietype GPL

Door Bart van Klaveren

Downloads en Best Buy Guide

26-09-2026 • 10:00

1

Submitter: RobbyTown

Bron: phpBB

Update-historie

10:00 phpBB 3.3.19 1
09-06 phpBB 3.3.17 6
03-05 phpBB 3.3.16 16
04-'25 phpBB 3.3.15 12
11-'24 phpBB 3.3.14 3
09-'24 phpBB 3.3.13 22
06-'22 phpBB 3.3.8 0
08-'20 phpBB 3.3.1 46
01-'20 phpBB 3.3 12
05-'19 phpBB 3.2.7 8
Meer historie

Reacties (1)

Sorteer op:

Weergave:


Om te kunnen reageren moet je ingelogd zijn