CVE-2025-62606

HIGH

my little forum <2.5.12 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0029
EPSS Percentile 21.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
My-Little-Forum/mylittleforum < 2.5.12
Published Oct 22, 2025
Tracked Since Feb 18, 2026