Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-37152 PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly s… Phpfusion No fix yet Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2020-37137 PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code … Phpfusion Mitigation only Fix from $2,3002026-02-05 MEDIUM 6.1 CVE-2023-53928 PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with e… Phpfusion No fix yet Fix from $1,6002025-12-17 MEDIUM 6.1 CVE-2014-8597 A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the sta… Phpfusion No fix yet Fix from $1,6002022-02-17 CRITICAL 9.6 CVE-2020-23754 Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary c… Phpfusion Mitigation only Fix from $2,3002021-11-02 HIGH 7.2 CVE-2021-40188 PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions… Phpfusion No fix yet Fix from $1,9502021-10-11 HIGH 7.2 CVE-2021-40189 PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], wh… Phpfusion No fix yet Fix from $1,9502021-10-11 MEDIUM 6.1 CVE-2021-40541 PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticate… Phpfusion No fix yet Fix from $1,6002021-10-11 MEDIUM 5.4 CVE-2020-23178 An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session repla… Php Fusion No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-23179 A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute… Php Fusion No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-23181 A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arb… Php Fusion No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-23182 The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious … Php Fusion No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-23184 A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers t… Php Fusion No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-23185 A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to exe… Php Fusion No fix yet Fix from $1,6002021-07-02 HIGH 8.8 CVE-2020-24949EPSS 68% Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server a… Php Fusion No fix yet Fix from $1,9502020-09-03 MEDIUM 5.4 CVE-2020-23658 PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php. Php Fusion No fix yet Fix from $1,6002020-08-26 MEDIUM 5.4 CVE-2020-12718 In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comme… Php Fusion No fix yet Fix from $1,6002020-05-08 MEDIUM 6.1 CVE-2020-12708 Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id para… Php Fusion No fix yet Fix from $1,6002020-05-07 HIGH 7.5 CVE-2014-8596 Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id… Php Fusion No fix yet Fix from $1,9502014-11-17 HIGH 7.5 CVE-2013-7375 SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbit… Php Fusion No fix yet Fix from $1,9502014-05-05 HIGH 10.0 CVE-2010-4931EPSS 16% Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot do… Php Fusion Mitigation only Fix from $1,9502011-10-09 MEDIUM 6.0 CVE-2009-0831 SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authen… Members Cv Module No fix yet Fix from $1,6002009-03-05 HIGH 7.5 CVE-2008-5946 SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter. Php Fusion No fix yet Fix from $1,9502009-01-22 HIGH 7.5 CVE-2008-5733 SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL command… Team Impact Ti Blog System Module No fix yet Fix from $1,9502008-12-26 HIGH 7.5 CVE-2008-5197 SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a det… Php Fusion No fix yet Fix from $1,9502008-11-21 HIGH 7.5 CVE-2008-5074 SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vi… Freshlinks Module No fix yet Fix from $1,9502008-11-14 HIGH 7.5 CVE-2008-4521 SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows re… World Of Warcraft Tracker Infusion Module No fix yet Fix from $1,9502008-10-09 HIGH 7.5 CVE-2008-4527 SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL command… Recepies Module No fix yet Fix from $1,9502008-10-09 MEDIUM 6.8 CVE-2008-2227 Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files vi… Forum Rank System No fix yet Fix from $1,6002008-05-14 HIGH 7.5 CVE-2007-5187 SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attac… Expanded Calendar Module No fix yet Fix from $1,9502007-10-03