Vulnerabilities (CVE)

Filtered by vendor Php-fusion Subscribe
Filtered by product Phpfusion
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28280 1 Php-fusion 1 Phpfusion 2022-04-25 4.3 MEDIUM 6.1 MEDIUM
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
CVE-2014-8597 1 Php-fusion 1 Phpfusion 2022-02-24 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.
CVE-2021-40541 1 Php-fusion 1 Phpfusion 2021-10-15 4.3 MEDIUM 6.1 MEDIUM
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
CVE-2020-35687 1 Php-fusion 1 Phpfusion 2021-02-02 4.3 MEDIUM 4.3 MEDIUM
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.