VYPR

PHP-Fusion CMS

by PHP-Fusion

CVEs (23)

  • CVE-2020-24949HigSep 3, 2020
    risk 0.66cvss 8.8epss 0.68

    Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

  • CVE-2020-23754CriNov 2, 2021
    risk 0.63cvss 9.6epss 0.02

    Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.

  • CVE-2019-12099HigMay 14, 2019
    risk 0.62cvss 8.8epss 0.17

    In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.

  • CVE-2020-12461HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.02

    PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over…

  • CVE-2020-14960HigJun 22, 2020
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,

  • CVE-2020-37152MedFeb 5, 2026
    risk 0.40cvss 6.1epss 0.00

    PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by…

  • CVE-2020-37137MedFeb 5, 2026
    risk 0.40cvss 6.1epss 0.01

    PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content…

  • CVE-2014-8597MedFeb 17, 2022
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

  • CVE-2020-17450MedAug 12, 2020
    risk 0.40cvss 6.1epss 0.01

    PHP-Fusion 9.03 allows XSS on the preview page.

  • CVE-2020-12708MedMay 7, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.

  • CVE-2020-12706MedMay 7, 2020
    risk 0.38cvss 5.4epss 0.03

    Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php

  • CVE-2020-23185MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2020-23184MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.

  • CVE-2020-23182MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.

  • CVE-2020-23181MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field.

  • CVE-2020-23179MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.

  • CVE-2020-23178MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.

  • CVE-2020-23658MedAug 26, 2020
    risk 0.35cvss 5.4epss 0.00

    PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.

  • CVE-2020-17449MedAug 12, 2020
    risk 0.35cvss 5.4epss 0.01

    PHP-Fusion 9.03 allows XSS via the error_log file.

  • CVE-2020-12718MedMay 8, 2020
    risk 0.35cvss 5.4epss 0.01

    In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.

Page 1 of 2