Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Php Fusion HIGH 8.8
CVE-2019-12099EPSS 18%

In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput…

Fix: 9.03.00+
Fix from $1,950 2019-05-14
Php Fusion MEDIUM 5.4
CVE-2015-8375

Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

Patch available
Fix from $1,600 2017-09-25
Php Fusion HIGH 7.5
CVE-2014-8596

Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id…

No fix yet
Fix from $1,950 2014-11-17
Php Fusion HIGH 7.5
CVE-2013-7375

SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbit…

No fix yet
Fix from $1,950 2014-05-05
Php Fusion HIGH 7.5
CVE-2013-1803

Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby para…

Fix: after 7.02.05
Fix from $1,950 2014-05-05
Php Fusion MEDIUM 6.5
CVE-2013-1806EPSS 8%

Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via…

Fix: after 7.02.05
Fix from $1,600 2014-04-30
Php Fusion MEDIUM 5.0
CVE-2013-1807EPSS 8%

PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow …

Fix: after 7.02.05
Fix from $1,600 2014-04-30
Php Fusion HIGH 10.0
CVE-2010-4931EPSS 16%

Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot do…

Mitigation only
Fix from $1,950 2011-10-09
Members Cv Module MEDIUM 6.0
CVE-2009-0831

SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authen…

No fix yet
Fix from $1,600 2009-03-05
Php Fusion HIGH 7.5
CVE-2008-5946

SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

No fix yet
Fix from $1,950 2009-01-22
Team Impact Ti Blog System Module HIGH 7.5
CVE-2008-5733

SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2008-12-26
Php Fusion MEDIUM 6.8
CVE-2008-5335

SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute a…

Patch available
Fix from $1,600 2008-12-05
The Kroax Module HIGH 7.5
CVE-2008-5196

SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary…

Fix: after 4.42
Fix from $1,950 2008-11-21
Php Fusion HIGH 7.5
CVE-2008-5197

SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a det…

No fix yet
Fix from $1,950 2008-11-21
Freshlinks Module HIGH 7.5
CVE-2008-5074

SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vi…

No fix yet
Fix from $1,950 2008-11-14
World Of Warcraft Tracker Infusion Module HIGH 7.5
CVE-2008-4521

SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows re…

No fix yet
Fix from $1,950 2008-10-09
Recepies Module HIGH 7.5
CVE-2008-4527

SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2008-10-09
Forum Rank System MEDIUM 6.8
CVE-2008-2227

Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files vi…

No fix yet
Fix from $1,600 2008-05-14
Php Fusion MEDIUM 6.0
CVE-2008-1918

SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is know…

Patch available
Fix from $1,600 2008-04-23
Expanded Calendar Module HIGH 7.5
CVE-2007-5187

SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attac…

No fix yet
Fix from $1,950 2007-10-03