Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Glfusion MEDIUM 6.1
CVE-2021-45843

glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the …

No fix yet
Fix from $1,600 2022-09-29
Glfusion CRITICAL 9.8
CVE-2021-44949

glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.

No fix yet
Fix from $2,300 2021-12-14
Glfusion CRITICAL 9.1
CVE-2021-44935

glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack re…

No fix yet
Fix from $2,300 2021-12-14
Glfusion MEDIUM 5.3
CVE-2021-44937

glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox …

No fix yet
Fix from $1,600 2021-12-14
Glfusion HIGH 7.5
CVE-2009-4796

Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier a…

Fix: after 1.1.2
Fix from $1,950 2010-04-22
Glfusion HIGH 7.5
CVE-2009-1282

SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands…

Fix: after 1.1.2
Fix from $1,950 2009-04-09
Glfusion MEDIUM 6.8
CVE-2009-1283

glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privile…

Fix: after 1.1.2
Fix from $1,600 2009-04-09