← Back

Mylittleforum

mylittleforum

9 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mylittleforum
1My Little Forum
Mar 17, 2026
Feb 9, 2026
8.7 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attacke...Show more
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature, trigger Phar deserialization through BBCode [img] tag processing, and exploit Smarty 4.1.0 POP chain to achieve arbitrary file deletion. This vulnerability is fixed in 20260208.1.Show less
1Mylittleforum
1My Little Forum
Nov 21, 2024
May 21, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
1Mylittleforum
1My Little Forum
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
my little forum 2.4.12 allows CSRF for deletion of users.
1Mylittleforum
1My Little Forum
Nov 21, 2024
Aug 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
1Mylittleforum
1My Little Forum
Nov 21, 2024
Aug 5, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
1Mylittleforum
1My Little Forum
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php.
1Mylittleforum
1My Little Forum
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.p...Show more
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.Show less
1Mylittleforum
1My Little Forum
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) board_entry.php or (b) forum_entry.php.Show less
1Mylittleforum
1My Little Forum
Apr 29, 2026
Jun 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.