PHP-Fusion / Phpfusion
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-37152 | PHP-Fusion 9.03.50 panels.php - Cross-Site Scripting (XSS) | MEDIUM | 5.1 | Feb 5, 2026 |
| CVE-2020-37137 | PHP-Fusion 9.03.50 - 'panels.php' Eval Injection | HIGH | 8.6 | Feb 5, 2026 |
| CVE-2020-36996 | PHPFusion 9.03.50 - Persistent Cross-Site Scripting | MEDIUM | 5.1 | Jan 30, 2026 |
| CVE-2023-53928 | PHPFusion 9.10.30 Stored Cross-Site Scripting via File Manager Upload | MEDIUM | 5.1 | Dec 17, 2025 |
| CVE-2023-4480 | Arbitrary File Read in Fusion File Manager | MEDIUM | 5.5 | Sep 5, 2023 |
| CVE-2023-2453 | Local file Inclusion (LFI) in Forum Infusion via Directory Traversal | HIGH | 8.8 | Sep 5, 2023 |
| CVE-2022-3152 | Unverified Password Change in phpfusion/phpfusion | HIGH | 8.8 | Sep 7, 2022 |
| CVE-2014-8597 | A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parame… | MEDIUM | 6.1 | Feb 17, 2022 |
| CVE-2020-23754 | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via t… | CRITICAL | 9.6 | Nov 2, 2021 |
| CVE-2021-40188 | PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as "… | HIGH | 7.2 | Oct 11, 2021 |
| CVE-2021-40189 | PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an att… | HIGH | 7.2 | Oct 11, 2021 |
| CVE-2021-40541 | PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can… | MEDIUM | 6.1 | Oct 11, 2021 |
| CVE-2021-28280 | CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML | MEDIUM | 6.1 | Apr 29, 2021 |
| CVE-2020-35687 | PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. | MEDIUM | 4.3 | Jan 13, 2021 |
Showing 1 to 13 of 13 CVEs