PHP-Fusion CMS
by PHP-Fusion
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12438 | Med | 0.35 | 5.4 | 0.01 | Apr 28, 2020 | An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags. | ||
| CVE-2020-23702 | Med | 0.31 | 4.8 | 0.01 | Jul 7, 2021 | Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php. | ||
| CVE-2020-15041 | Med | 0.31 | 4.8 | 0.01 | Jun 24, 2020 | PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field. |
- risk 0.35cvss 5.4epss 0.01
An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.
- risk 0.31cvss 4.8epss 0.01
Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.
- risk 0.31cvss 4.8epss 0.01
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
Page 2 of 2