CVE-2023-24956: Forget Heart Message Box Project Forget Heart Message Box

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.

Affected products

Published 2023-02-01. Last modified 2026-06-17.