Known Vulnerabilities for Phpfusion by Php-fusion
Listed below are 10 of the newest known vulnerabilities associated with "Phpfusion" by "Php-fusion".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-4480 json | Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker ... | 5.5 - MEDIUM | 2023-09-05 | 2023-09-08 |
| CVE-2023-2453 json | There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently pass... | 8.8 - HIGH | 2023-09-05 | 2023-09-08 |
| CVE-2022-3152 json | Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. | 8.8 - HIGH | 2022-09-07 | 2022-09-12 |
| CVE-2021-40541 json | PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() ... | 6.1 - MEDIUM | 2021-10-11 | 2021-10-15 |
| CVE-2021-40189 json | PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/t... | 7.2 - HIGH | 2021-10-11 | 2021-10-19 |
| CVE-2021-40188 json | PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not f... | 7.2 - HIGH | 2021-10-11 | 2021-10-18 |
| CVE-2021-28280 json | CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitra... | 6.1 - MEDIUM | 2021-04-29 | 2022-04-25 |
| CVE-2020-35687 json | PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on be... | 4.3 - MEDIUM | 2021-01-13 | 2021-02-02 |
| CVE-2020-23754 json | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attacker... | 9.6 - CRITICAL | 2021-11-02 | 2021-11-03 |
| CVE-2014-8597 json | A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web sc... | 6.1 - MEDIUM | 2022-02-17 | 2022-02-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php-fusion | Phpfusion | 9.03.90 | |||
| Application | Php-fusion | Phpfusion | 9.03.80 | |||
| Application | Php-fusion | Phpfusion | 9.03.70 | |||
| Application | Php-fusion | Phpfusion | 9.03.60 | |||
| Application | Php-fusion | Phpfusion | 9.03.50 | |||
| Application | Php-fusion | Phpfusion | 9.03.40 | |||
| Application | Php-fusion | Phpfusion | 9.03.30 | |||
| Application | Php-fusion | Phpfusion | 9.03.100 | |||
| Application | Php-fusion | Phpfusion | 8.00.70 | |||
| Application | Php-fusion | Phpfusion | 8.00.60 | |||
| Application | Php-fusion | Phpfusion | 8.00.50 | |||
| Application | Php-fusion | Phpfusion | 8.00.40 |