Skip to main content

Vendor archive

mylittleforum CVEs

Beta · best-effort

9 CVEs tagged to vendor mylittleforum0 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-25923

Published Feb 9, 2026

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// pro…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2015-1435

Published Feb 16, 2015

Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1434

Published Feb 16, 2015

Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1475

Published Feb 4, 2015

Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) ca…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2133

Published Jun 2, 2010

SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1