PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24838
http://www.securityfocus.com/archive/1/425630/100/0/threaded