CVE Feed

    Dashboard / CVE / CVE-2026-25923

    CVE-2026-25923

    my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature, trigger Phar deserialization through BBCode [img] tag processing, and exploit Smarty 4.1.0 POP chain to achieve arbitrary file deletion. This vulnerability is fixed in 20260208.1.

    Published:Feb 9, 2026
    Last Modified:Apr 17, 2026
    EPS:Feb 9, 2026
    EPSS Score:0.00077
    CVSS Score:9.1

    Affected Products

    Vendor
    My Little Forum
    Product
    My Little Forum
    Vendor
    Mylittleforum
    Product
    My Little Forum

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High