AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-1130

HIGH · CVSS 7.5 EPSS 1.08%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-06-21 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It involves a SQL injection risk. It may lead to a denial-of-service condition.

CVE
CVE-2011-1130
Severity
HIGH
CVSS
7.5
EPSS
1.08%

Original NVD Description

Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value, related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.