PT-2026-31560 · Code Projects · Simple It Discussion Forum

Christychen11

·

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2026-5828

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5828

Affected Products

Simple It Discussion Forum