Vulnerabilities > PHP Fusion > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-29 CVE-2021-28280 Cross-site Scripting vulnerability in PHP-Fusion PHPfusion 9.03.110
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
network
low complexity
php-fusion CWE-79
6.1
2021-01-13 CVE-2020-35687 Cross-Site Request Forgery (CSRF) vulnerability in PHP-Fusion PHPfusion 9.03.90
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
network
low complexity
php-fusion CWE-352
4.3
2021-01-03 CVE-2020-35952 Unspecified vulnerability in PHP-Fusion
login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.
network
low complexity
php-fusion
6.5
2020-08-26 CVE-2020-23658 Cross-site Scripting vulnerability in PHP-Fusion 9.03.60
PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.
network
low complexity
php-fusion CWE-79
5.4
2020-08-12 CVE-2020-17450 Cross-site Scripting vulnerability in PHP-Fusion 9.0/9.00/9.03
PHP-Fusion 9.03 allows XSS on the preview page.
network
low complexity
php-fusion CWE-79
6.1
2020-08-12 CVE-2020-17449 Cross-site Scripting vulnerability in PHP-Fusion 9.0/9.00/9.03
PHP-Fusion 9.03 allows XSS via the error_log file.
network
low complexity
php-fusion CWE-79
5.4
2020-06-24 CVE-2020-15041 Cross-site Scripting vulnerability in PHP-Fusion 9.03.60
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
network
low complexity
php-fusion CWE-79
4.8
2020-05-08 CVE-2020-12718 Cross-site Scripting vulnerability in PHP-Fusion 9.03.50
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature.
network
low complexity
php-fusion CWE-79
5.4
2020-05-07 CVE-2020-12708 Cross-site Scripting vulnerability in PHP-Fusion 9.03.50
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php.
network
low complexity
php-fusion CWE-79
6.1
2020-05-07 CVE-2020-12706 Cross-site Scripting vulnerability in PHP-Fusion 9.03.50
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php
network
low complexity
php-fusion CWE-79
5.4