VYPR

Vendor CVEs

PHP-Fusion

All CVEs

92 total · sorted by risk
  • CVE-2020-24949HigSep 3, 2020
    risk 0.66cvss 8.8epss 0.68

    Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

  • CVE-2020-23754CriNov 2, 2021
    risk 0.63cvss 9.6epss 0.02

    Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.

  • CVE-2019-12099HigMay 14, 2019
    risk 0.62cvss 8.8epss 0.18

    In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.

  • CVE-2023-2453HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and…

  • CVE-2020-12461HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.02

    PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over…

  • CVE-2021-40189HigOct 11, 2021
    risk 0.47cvss 7.2epss 0.02

    PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.

  • CVE-2021-40188HigOct 11, 2021
    risk 0.47cvss 7.2epss 0.01

    PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.

  • CVE-2020-14960HigJun 22, 2020
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,

  • CVE-2020-36996MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated,…

  • CVE-2020-35952MedJan 3, 2021
    risk 0.42cvss 6.5epss 0.01

    login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.

  • CVE-2020-37152MedFeb 5, 2026
    risk 0.40cvss 6.1epss 0.00

    PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by…

  • CVE-2020-37137MedFeb 5, 2026
    risk 0.40cvss 6.1epss 0.01

    PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content…

  • CVE-2014-8597MedFeb 17, 2022
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

  • CVE-2021-40541MedOct 11, 2021
    risk 0.40cvss 6.1epss 0.01

    PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.

  • CVE-2020-17450MedAug 12, 2020
    risk 0.40cvss 6.1epss 0.01

    PHP-Fusion 9.03 allows XSS on the preview page.

  • CVE-2020-12708MedMay 7, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.

  • CVE-2020-12706MedMay 7, 2020
    risk 0.38cvss 5.4epss 0.03

    Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php

  • CVE-2023-4480MedSep 5, 2023
    risk 0.36cvss 5.5epss 0.01

    Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the privileges of the running process.…

  • CVE-2023-53928MedDec 17, 2025
    risk 0.35cvss 5.4epss 0.00

    PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially…

  • CVE-2020-23185MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2020-23184MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.

  • CVE-2020-23182MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.

  • CVE-2020-23181MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field.

  • CVE-2020-23179MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.

  • CVE-2020-23178MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.

  • CVE-2020-23658MedAug 26, 2020
    risk 0.35cvss 5.4epss 0.00

    PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.

  • CVE-2020-17449MedAug 12, 2020
    risk 0.35cvss 5.4epss 0.01

    PHP-Fusion 9.03 allows XSS via the error_log file.

  • CVE-2020-12718MedMay 8, 2020
    risk 0.35cvss 5.4epss 0.01

    In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.

  • CVE-2020-12438MedApr 28, 2020
    risk 0.35cvss 5.4epss 0.01

    An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.

  • CVE-2020-23702MedJul 7, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.

  • CVE-2020-35687MedJan 13, 2021
    risk 0.31cvss 4.3epss 0.01

    PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

  • CVE-2020-15041MedJun 24, 2020
    risk 0.31cvss 4.8epss 0.01

    PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.

  • CVE-2015-8375MedSep 25, 2017
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

  • CVE-2013-1807Apr 30, 2014
    risk 0.04cvss epss 0.08

    PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

  • CVE-2013-1806Apr 30, 2014
    risk 0.04cvss epss 0.08

    Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files…

  • CVE-2010-4931Oct 9, 2011
    risk 0.04cvss epss 0.16

    Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party

  • CVE-2006-2330May 12, 2006
    risk 0.04cvss epss 0.08

    PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses…

  • CVE-2005-2075Jun 29, 2005
    risk 0.04cvss epss 0.07

    PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory…

  • CVE-2004-1724Aug 18, 2004
    risk 0.04cvss epss 0.07

    The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain…

  • CVE-2014-8596Nov 17, 2014
    risk 0.03cvss epss 0.03

    Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.

  • CVE-2013-7375May 5, 2014
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.

  • CVE-2013-1803May 5, 2014
    risk 0.03cvss epss 0.04

    Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated users with certain permissions to execute arbitrary SQL commands via a (2)…

  • CVE-2013-1804Apr 29, 2014
    risk 0.03cvss epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions to inject arbitrary web…

  • CVE-2012-6043Nov 26, 2012
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

  • CVE-2010-4791Apr 27, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.

  • CVE-2011-0512Jan 20, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the team_id parameter.

  • CVE-2009-0832Mar 5, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.

  • CVE-2009-0831Mar 5, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.

  • CVE-2008-5946Jan 22, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

  • CVE-2008-5733Dec 26, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.

Page 1 of 2