Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpfusion MEDIUM 6.1
CVE-2020-37152

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly s…

No fix yet
Fix from $1,600 2026-02-05
Phpfusion CRITICAL 9.8
CVE-2020-37137

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2026-02-05
Phpfusion MEDIUM 6.1
CVE-2023-53928

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with e…

No fix yet
Fix from $1,600 2025-12-17
Phpfusion HIGH 8.8
CVE-2023-2453

There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ s…

Fix: after 9.10.30
Fix from $1,950 2023-09-05
Phpfusion MEDIUM 5.5
CVE-2023-4480

Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request th…

Fix: after 9.10.30
Fix from $1,600 2023-09-05
Php Fusion HIGH 8.1
CVE-2021-3172

An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.

Fix: 9.10.00+
Fix from $1,950 2023-02-17
Phpfusion HIGH 8.8
CVE-2022-3152

Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.

Fix: 9.10.20+
Fix from $1,950 2022-09-07
Phpfusion MEDIUM 6.1
CVE-2014-8597

A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the sta…

No fix yet
Fix from $1,600 2022-02-17
Phpfusion CRITICAL 9.6
CVE-2020-23754

Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2021-11-02
Phpfusion HIGH 7.2
CVE-2021-40188

PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions…

No fix yet
Fix from $1,950 2021-10-11
Phpfusion HIGH 7.2
CVE-2021-40189

PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], wh…

No fix yet
Fix from $1,950 2021-10-11
Phpfusion MEDIUM 6.1
CVE-2021-40541

PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticate…

No fix yet
Fix from $1,600 2021-10-11
Php Fusion MEDIUM 5.4
CVE-2020-23178

An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session repla…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23179

A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23181

A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arb…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23182

The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious …

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23184

A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers t…

No fix yet
Fix from $1,600 2021-07-02
Php Fusion MEDIUM 5.4
CVE-2020-23185

A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to exe…

No fix yet
Fix from $1,600 2021-07-02
Phpfusion MEDIUM 6.1
CVE-2021-28280

CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML

Patch available
Fix from $1,600 2021-04-29
Php Fusion MEDIUM 6.5
CVE-2020-35952

login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and inco…

Fix: 9.03.90+
Fix from $1,600 2021-01-03
Php Fusion HIGH 8.8
CVE-2020-24949EPSS 68%

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server a…

No fix yet
Fix from $1,950 2020-09-03
Php Fusion MEDIUM 5.4
CVE-2020-23658

PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.

No fix yet
Fix from $1,600 2020-08-26
Php Fusion MEDIUM 6.1
CVE-2020-17450

PHP-Fusion 9.03 allows XSS on the preview page.

Fix: after 9.03
Fix from $1,600 2020-08-12
Php Fusion MEDIUM 5.4
CVE-2020-17449

PHP-Fusion 9.03 allows XSS via the error_log file.

Fix: after 9.03
Fix from $1,600 2020-08-12
Php Fusion HIGH 7.2
CVE-2020-14960

A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,

Patch available
Fix from $1,950 2020-06-22
Php Fusion MEDIUM 5.4
CVE-2020-12718

In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comme…

No fix yet
Fix from $1,600 2020-05-08
Php Fusion MEDIUM 6.1
CVE-2020-12708

Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id para…

No fix yet
Fix from $1,600 2020-05-07
Php Fusion MEDIUM 5.4
CVE-2020-12706

Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go paramete…

Patch available
Fix from $1,600 2020-05-07
Php Fusion HIGH 8.8
CVE-2020-12461

PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that…

Patch available
Fix from $1,950 2020-04-29
Php Fusion MEDIUM 5.4
CVE-2020-12438

An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS i…

Patch available
Fix from $1,600 2020-04-28