CVE-2018-25362: Fyffe PHP-Twitter-Clone

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials.

Affected products

  • Fyffe PHP-Twitter-Clone: version 1.0 only

Published 2026-05-25. Last modified 2026-07-23.