Known Vulnerabilities for products from Glfusion
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Glfusion".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-45843 json | glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request param... | 6.1 - MEDIUM | 2022-09-29 | 2022-09-30 |
| CVE-2021-44949 json | glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. | 9.8 - CRITICAL | 2021-12-14 | 2023-08-08 |
| CVE-2021-44948 json | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-44942. Reason: This candidate is a duplicate of CVE-2021-... | Not Provided | 2021-12-14 | 2023-11-07 |
| CVE-2021-44942 json | glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavio... | 4.3 - MEDIUM | 2021-12-14 | 2021-12-15 |
| CVE-2021-44937 json | glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can re... | 5.3 - MEDIUM | 2021-12-14 | 2022-07-12 |
| CVE-2021-44935 json | glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker ca... | 9.1 - CRITICAL | 2021-12-14 | 2021-12-15 |
| CVE-2013-1466 json | Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary w... | Not Provided | 2014-02-05 | 2026-04-29 |
| CVE-2009-4796 json | Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFu... | Not Provided | 2010-04-22 | 2026-04-29 |
| CVE-2009-1283 json | glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote a... | Not Provided | 2009-04-09 | 2026-04-23 |
| CVE-2009-1282 json | SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execut... | Not Provided | 2009-04-09 | 2026-04-23 |
| CVE-2009-1281 json | Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or H... | Not Provided | 2009-04-09 | 2026-04-23 |
| CVE-2009-0455 json | Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and e... | Not Provided | 2009-02-11 | 2026-04-23 |