CVE-2023-24241: Forget Heart Message Box Project Forget Heart Message Box

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php.

Affected products

Published 2023-02-01. Last modified 2026-06-17.