CVE-2025-62606High· 8.8▾ Twilightmy little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15410High· 7.3A vulnerability was identified in code-projects Online Guitar Store 1.0
CVE-2025-15420High· 7.3A security vulnerability has been detected in Yonyou KSOA 9.0
CVE-2025-15212Medium· 6.3A vulnerability was detected in code-projects Refugee Food Management System 1.0
CVE-2025-14258High· 7.3A vulnerability has been found in itsourcecode Student Management System 1.0
CVE-2025-13567Medium· 6.3A vulnerability was detected in itsourcecode COVID Tracking System 1.0
CVE-2025-13289Medium· 6.3A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0