Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-45843 glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the … Glfusion No fix yet Fix from $1,6002022-09-29 CRITICAL 9.8 CVE-2021-44949 glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. Glfusion No fix yet Fix from $2,3002021-12-14 CRITICAL 9.1 CVE-2021-44935 glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack re… Glfusion No fix yet Fix from $2,3002021-12-14 MEDIUM 5.3 CVE-2021-44937 glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox … Glfusion No fix yet Fix from $1,6002021-12-14 HIGH 7.5 CVE-2009-4796 Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier a… Glfusion after 1.1.2 Fix from $1,9502010-04-22 HIGH 7.5 CVE-2009-1282 SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands… Glfusion after 1.1.2 Fix from $1,9502009-04-09 MEDIUM 6.8 CVE-2009-1283 glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privile… Glfusion after 1.1.2 Fix from $1,6002009-04-09