Vulnerabilities > PHP Fusion > Phpfusion > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-05 CVE-2023-2453 Inclusion of Functionality from Untrusted Control Sphere vulnerability in PHP-Fusion PHPfusion
There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement.
network
low complexity
php-fusion CWE-829
8.8
2022-09-07 CVE-2022-3152 Improper Authentication vulnerability in PHP-Fusion PHPfusion
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
network
low complexity
php-fusion CWE-287
8.8
2021-10-11 CVE-2021-40188 Unrestricted Upload of File with Dangerous Type vulnerability in PHP-Fusion PHPfusion 9.03.110
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability.
network
low complexity
php-fusion CWE-434
7.2
2021-10-11 CVE-2021-40189 Unrestricted Upload of File with Dangerous Type vulnerability in PHP-Fusion PHPfusion 9.03.110
PHPFusion 9.03.110 is affected by a remote code execution vulnerability.
network
low complexity
php-fusion CWE-434
7.2