fusionforge records
4 published records for vendor fusionforge.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2015-0850No exploit | The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a fusionforge · fusionforge · CWE-20 | Critical10.0 | — | 4.5% | Jun 2, 2015 |
39Monitor | CVE-2014-0468No exploit | Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploadfusionforge · fusionforge · CWE-434 | Critical9.8 | — | 0.5% | Jun 26, 2025 |
27Monitor | CVE-2013-1423No exploit | (1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) fusionforge · fusionforge · CWE-59 | Medium6.9 | — | 0.4% | Mar 13, 2013 |
23Monitor | CVE-2014-6275No exploit | FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default.fusionforge · fusionforge · CWE-200 | Medium5.9 | — | 0.9% | Jan 2, 2020 |
- CVE-2015-085041Plan
The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a
CriticalCVSS 10.0No exploitEPSS 4%fusionforge · fusionforgeJun 2, 2015
- CVE-2014-046839Monitor
Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have upload
CriticalCVSS 9.8No exploitEPSS 1%fusionforge · fusionforgeJun 26, 2025
- CVE-2013-142327Monitor
(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5)
MediumCVSS 6.9No exploitEPSS 0%fusionforge · fusionforgeMar 13, 2013
- CVE-2014-627523Monitor
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default.
MediumCVSS 5.9No exploitEPSS 1%fusionforge · fusionforgeJan 2, 2020