CVE-2020-25005: Heybbs Project Heybbs
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.
Affected products
- Heybbs Project Heybbs: version 1.2 only
Published 2020-09-03. Last modified 2026-06-17.