A XSS vulnerability has been discovered in phpBB 2.0.18. It was reported almost a month ago. The phpBB team has released version 2.0.19 in response to this vulnerability along with a path disclosure issue that existed in 2.0.18. I posted a lengthy example to the exploit here.