Vulnerabilities > Mylittleforum

DATE CVE VULNERABILITY TITLE RISK
2019-05-21 CVE-2019-12253 Cross-Site Request Forgery (CSRF) vulnerability in Mylittleforum MY Little Forum
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
network
low complexity
mylittleforum CWE-352
6.5
2018-08-20 CVE-2018-15569 Cross-Site Request Forgery (CSRF) vulnerability in Mylittleforum MY Little Forum 2.4.12
my little forum 2.4.12 allows CSRF for deletion of users.
network
low complexity
mylittleforum CWE-352
6.5
2018-08-05 CVE-2018-14937 Cross-site Scripting vulnerability in Mylittleforum MY Little Forum 2.4.12
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
network
low complexity
mylittleforum CWE-79
4.8
2018-08-05 CVE-2018-14936 Cross-site Scripting vulnerability in Mylittleforum MY Little Forum 2.4.12
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
network
low complexity
mylittleforum CWE-79
4.8