FOGProject / Fogproject
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-47689 | FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab | MEDIUM | 5.2 | Jul 21, 2026 |
| CVE-2026-47688 | FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules | HIGH | 8.2 | Jul 21, 2026 |
| CVE-2026-47687 | FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint | HIGH | 8.7 | Jul 21, 2026 |
| CVE-2026-47685 | FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page | HIGH | 8.7 | Jul 21, 2026 |
| CVE-2026-33739 | FOG has Stored XSS in Multiple Management Pages | MEDIUM | 5.7 | Mar 27, 2026 |
| CVE-2026-24138 | FOG vulnerable to unauthenticated SSRF via `/fog/service/getversion.php` | HIGH | 7.5 | Jan 23, 2026 |
| CVE-2025-58443 | FOG's authentication bypass leads to full SQL DB dump | CRITICAL | 9.9 | Sep 6, 2025 |
| CVE-2024-42349 | FOG has a Log Information Disclosure | MEDIUM | 5.3 | Aug 2, 2024 |
| CVE-2024-42348 | FOG leaks sensitive information (AD domain, username and password) | CRITICAL | 9.3 | Aug 2, 2024 |
| CVE-2024-41954 | FOG Weak file permissions | HIGH | 7.8 | Jul 31, 2024 |
| CVE-2024-41108 | FOG Sensitive Information Disclosure | HIGH | 7.5 | Jul 31, 2024 |
| CVE-2024-40645 | FOG Authenticated File Upload RCE | HIGH | 8.8 | Jul 31, 2024 |
| CVE-2024-39916 | NFS server misconfiguration allows file access outside the exported directory | MEDIUM | 6.4 | Jul 12, 2024 |
| CVE-2024-39914 | FOG has a command injection in /fog/management/export.php?filename= | CRITICAL | 9.8 | Jul 12, 2024 |
| CVE-2024-34477 | configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash… | HIGH | 7.8 | May 27, 2024 |
| CVE-2023-46237 | FOG path traversal via unauthenticated endpoint | MEDIUM | 5.8 | Oct 31, 2023 |
| CVE-2023-46236 | FOG SSRF via unauthenticated endpoint(s) | HIGH | 8.6 | Oct 31, 2023 |
| CVE-2023-46235 | FOG stored XSS on log screen via unsanitized request logging | MEDIUM | 6.1 | Oct 31, 2023 |
| CVE-2021-32243 | FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated). | HIGH | 8.8 | Jun 16, 2021 |
Showing 1 to 19 of 19 CVEs