Login/Register

Update Feed

phpBB 3.1.1

3 November 2014

phpBB version 3.1.1 is now available (security release).

Upgrading to phpBB 3.1.1


phpBB 3.1.1 can be upgraded to (or installed) using any of Installatron's products. Use Installatron's optional Automatic Update feature to automatically apply phpBB updates as new versions are released, or use Installatron's Clone feature to duplicate an existing phpBB install to test the 3.1.1 upgrade prior to applying it live. Get started managing your phpBB installations with Installatron

What's New in phpBB 3.1.1


This release addresses a minor vulnerability as well as several usability issues that have been brought to our attention. If you installed phpBB 3.1.0, please update to 3.1.1.

Firstly, despite our best efforts and a full security audit of the 3.1 codebase by SektionEins, Dingjie Yang of Qualys, Inc. discovered an XSS vulnerability that may be utilized against users of older browsers. Our tests indicate that this does not seem to affect major browsers released after 2009, making all browsers officially supported by phpBB 3.1 immune and around 99.9% of phpBB.com visitors unaffected. Nevertheless, we are not taking any chances and urge everyone to update. Thanks to Mr. Yang for bringing this to our attention.

Secondly, we are removing the "Send a copy of this email to yourself" feature from the contact page for guests to avoid it being used for sending undesired emails from the board.

Lastly, we are fixing several usability issues that were preventing some users from having a smooth experience while updating from 3.0 to 3.1. The notable ones are:

© 2004 - 2023 Installatron LLC. All rights reserved. Privacy Policy.