Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Phpfusion MEDIUM 6.1
CVE-2020-37152

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly s…

No fix yet
Fix from $1,600 2026-02-05
Phpfusion CRITICAL 9.8
CVE-2020-37137

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2026-02-05
Phpfusion MEDIUM 6.1
CVE-2023-53928

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with e…

No fix yet
Fix from $1,600 2025-12-17
Phpfusion MEDIUM 6.1
CVE-2014-8597

A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the sta…

No fix yet
Fix from $1,600 2022-02-17
Phpfusion CRITICAL 9.6
CVE-2020-23754

Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2021-11-02
Phpfusion HIGH 7.2
CVE-2021-40188

PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions…

No fix yet
Fix from $1,950 2021-10-11
Phpfusion HIGH 7.2
CVE-2021-40189

PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], wh…

No fix yet
Fix from $1,950 2021-10-11
Phpfusion MEDIUM 6.1
CVE-2021-40541

PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticate…

No fix yet
Fix from $1,600 2021-10-11
Php Fusion MEDIUM 5.4
CVE-2020-23178

An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session repla…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23179

A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23181

A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arb…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23182

The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious …

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23184

A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers t…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23185

A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to exe…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion HIGH 8.8
CVE-2020-24949EPSS 68%

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server a…

No fix yet
Fix from $1,950 2020-09-03
Php Fusion MEDIUM 5.4
CVE-2020-23658

PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.

No fix yet
Fix from $1,600 2020-08-26
Php Fusion MEDIUM 5.4
CVE-2020-12718

In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comme…

No fix yet
Fix from $1,600 2020-05-08
Php Fusion MEDIUM 6.1
CVE-2020-12708

Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id para…

No fix yet
Fix from $1,600 2020-05-07
Php Fusion HIGH 7.5
CVE-2014-8596

Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id…

No fix yet
Fix from $1,950 2014-11-17
Php Fusion HIGH 7.5
CVE-2013-7375

SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbit…

No fix yet
Fix from $1,950 2014-05-05
Php Fusion HIGH 10.0
CVE-2010-4931EPSS 16%

Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot do…

Mitigation only
Fix from $1,950 2011-10-09
Members Cv Module MEDIUM 6.0
CVE-2009-0831

SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authen…

No fix yet
Fix from $1,600 2009-03-05
Php Fusion HIGH 7.5
CVE-2008-5946

SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

No fix yet
Fix from $1,950 2009-01-22
Team Impact Ti Blog System Module HIGH 7.5
CVE-2008-5733

SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2008-12-26
Php Fusion HIGH 7.5
CVE-2008-5197

SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a det…

No fix yet
Fix from $1,950 2008-11-21
Freshlinks Module HIGH 7.5
CVE-2008-5074

SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vi…

No fix yet
Fix from $1,950 2008-11-14
World Of Warcraft Tracker Infusion Module HIGH 7.5
CVE-2008-4521

SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows re…

No fix yet
Fix from $1,950 2008-10-09
Recepies Module HIGH 7.5
CVE-2008-4527

SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2008-10-09
Forum Rank System MEDIUM 6.8
CVE-2008-2227

Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files vi…

No fix yet
Fix from $1,600 2008-05-14
Expanded Calendar Module HIGH 7.5
CVE-2007-5187

SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attac…

No fix yet
Fix from $1,950 2007-10-03