Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-12099EPSS 18%
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput…
Php Fusion
9.03.00+
MEDIUM 5.4
CVE-2015-8375
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
Php Fusion
Patch available
HIGH 7.5
CVE-2014-8596
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id…
Php Fusion
No fix yet
HIGH 7.5
CVE-2013-7375
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbit…
Php Fusion
No fix yet
HIGH 7.5
CVE-2013-1803
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby para…
Php Fusion
after 7.02.05
MEDIUM 6.5
CVE-2013-1806EPSS 8%
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via…
Php Fusion
after 7.02.05
MEDIUM 5.0
CVE-2013-1807EPSS 8%
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow …
Php Fusion
after 7.02.05
HIGH 10.0
CVE-2010-4931EPSS 16%
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot do…
Php Fusion
Mitigation only
MEDIUM 6.0
CVE-2009-0831
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authen…
Members Cv Module
No fix yet
HIGH 7.5
CVE-2008-5946
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
Php Fusion
No fix yet
HIGH 7.5
CVE-2008-5733
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL command…
Team Impact Ti Blog System Module
No fix yet
MEDIUM 6.8
CVE-2008-5335
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute a…
Php Fusion
Patch available
HIGH 7.5
CVE-2008-5196
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary…
The Kroax Module
after 4.42
HIGH 7.5
CVE-2008-5197
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a det…
Php Fusion
No fix yet
HIGH 7.5
CVE-2008-5074
SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vi…
Freshlinks Module
No fix yet
HIGH 7.5
CVE-2008-4521
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows re…
World Of Warcraft Tracker Infusion Module
No fix yet
HIGH 7.5
CVE-2008-4527
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL command…
Recepies Module
No fix yet
MEDIUM 6.8
CVE-2008-2227
Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files vi…
Forum Rank System
No fix yet
MEDIUM 6.0
CVE-2008-1918
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is know…
Php Fusion
Patch available
HIGH 7.5
CVE-2007-5187
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attac…
Expanded Calendar Module
No fix yet