Mylittleforum
Mylittleforum MY Little Forum: vulnerabilidades y CVE
Mylittleforum MY Little Forum tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25923 | Alta (8.7) | 0.65% | — | 9 feb 2026 | my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing… |
| CVE-2025-62606 | Alta (8.8) | 0.40% | — | 22 oct 2025 | my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature… |
| CVE-2019-12253 | Media (6.5) | 0.60% | — | 21 may 2019 | my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting. |
| CVE-2018-15569 | Media (6.5) | 0.41% | — | 20 ago 2018 | my little forum 2.4.12 allows CSRF for deletion of users. |
| CVE-2018-14937 | Media (4.8) | 0.91% | — | 5 ago 2018 | The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field. |
| CVE-2018-14936 | Media (4.8) | 0.91% | — | 5 ago 2018 | The Add page option in my little forum 2.4.12 allows XSS via the Title field. |
| CVE-2015-1435 | Media (4.3) | 2.4% | — | 16 feb 2015 | Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php. |
| CVE-2015-1434 | Media (6.5) | 1.8% | — | 16 feb 2015 | Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to… |
| CVE-2015-1475 | Media (4.3) | 1.9% | — | 4 feb 2015 | Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3)… |
| CVE-2010-2133 | Alta (7.5) | 2.0% | — | 2 jun 2010 | SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.