CVE-2012-6520: Wikidforum

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.

Affected products

Published 2013-01-24. Last modified 2026-06-16.