Vulnerabilities (CVE)

Filtered by vendor Glfusion Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44937 1 Glfusion 1 Glfusion 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied.
CVE-2021-44942 1 Glfusion 1 Glfusion 2021-12-15 4.3 MEDIUM 4.3 MEDIUM
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.