PHP-Fusion CMS
by PHP-Fusion
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24949 | Hig | 0.66 | 8.8 | 0.68 | Sep 3, 2020 | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE). | ||
| CVE-2020-23754 | Cri | 0.63 | 9.6 | 0.02 | Nov 2, 2021 | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature. | ||
| CVE-2019-12099 | Hig | 0.62 | 8.8 | 0.17 | May 14, 2019 | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload. | ||
| CVE-2020-12461 | Hig | 0.57 | 8.8 | 0.02 | Apr 29, 2020 | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over… | ||
| CVE-2020-14960 | Hig | 0.47 | 7.2 | 0.02 | Jun 22, 2020 | A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter, | ||
| CVE-2020-37152 | Med | 0.40 | 6.1 | 0.00 | Feb 5, 2026 | PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by… | ||
| CVE-2020-37137 | Med | 0.40 | 6.1 | 0.01 | Feb 5, 2026 | PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content… | ||
| CVE-2014-8597 | Med | 0.40 | 6.1 | 0.01 | Feb 17, 2022 | A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel. | ||
| CVE-2020-17450 | Med | 0.40 | 6.1 | 0.01 | Aug 12, 2020 | PHP-Fusion 9.03 allows XSS on the preview page. | ||
| CVE-2020-12708 | Med | 0.40 | 6.1 | 0.01 | May 7, 2020 | Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043. | ||
| CVE-2020-12706 | Med | 0.38 | 5.4 | 0.03 | May 7, 2020 | Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php | ||
| CVE-2020-23185 | Med | 0.35 | 5.4 | 0.00 | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2020-23184 | Med | 0.35 | 5.4 | 0.00 | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field. | ||
| CVE-2020-23182 | Med | 0.35 | 5.4 | 0.01 | Jul 2, 2021 | The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel. | ||
| CVE-2020-23181 | Med | 0.35 | 5.4 | 0.00 | Jul 2, 2021 | A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field. | ||
| CVE-2020-23179 | Med | 0.35 | 5.4 | 0.00 | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field. | ||
| CVE-2020-23178 | Med | 0.35 | 5.4 | 0.01 | Jul 2, 2021 | An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user. | ||
| CVE-2020-23658 | Med | 0.35 | 5.4 | 0.00 | Aug 26, 2020 | PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php. | ||
| CVE-2020-17449 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2020 | PHP-Fusion 9.03 allows XSS via the error_log file. | ||
| CVE-2020-12718 | Med | 0.35 | 5.4 | 0.01 | May 8, 2020 | In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle. |
- risk 0.66cvss 8.8epss 0.68
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
- risk 0.63cvss 9.6epss 0.02
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
- risk 0.62cvss 8.8epss 0.17
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.
- risk 0.57cvss 8.8epss 0.02
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over…
- risk 0.47cvss 7.2epss 0.02
A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,
- risk 0.40cvss 6.1epss 0.00
PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by…
- risk 0.40cvss 6.1epss 0.01
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content…
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.
- risk 0.40cvss 6.1epss 0.01
PHP-Fusion 9.03 allows XSS on the preview page.
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
- risk 0.38cvss 5.4epss 0.03
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php
- risk 0.35cvss 5.4epss 0.00
A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.
- risk 0.35cvss 5.4epss 0.01
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.
- risk 0.35cvss 5.4epss 0.00
A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field.
- risk 0.35cvss 5.4epss 0.00
A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.
- risk 0.35cvss 5.4epss 0.01
An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.
- risk 0.35cvss 5.4epss 0.00
PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.
- risk 0.35cvss 5.4epss 0.01
PHP-Fusion 9.03 allows XSS via the error_log file.
- risk 0.35cvss 5.4epss 0.01
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.
Page 1 of 2