---
id: CVE-2025-62606
title: >-
  my little forum is a PHP and MySQL based internet forum that displays the
  messages in classical threaded view
summary: >-
  my little forum is a PHP and MySQL based internet forum that displays the
  messages in classical threaded view. Prior to version 2.5.12, an authenticated
  SQL injection vulnerability in the bookmark reordering feature allows any
  logged-in …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
published: '2025-10-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62606'
references:
  - url: 'https://github.com/My-Little-Forum/mylittleforum/releases/tag/20251021.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/My-Little-Forum/mylittleforum/security/advisories/GHSA-m8hj-c6gr-6h6v
    label: security-advisories@github.com
  - url: >-
      https://github.com/My-Little-Forum/mylittleforum/security/advisories/GHSA-m8hj-c6gr-6h6v
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00323
epssPercentile: 0.2291
ingestedAt: '2026-09-30T23:29:32.445Z'
---

## Overview

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
