PHP-Fusion records
62 published records for vendor php-fusion.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 20
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')21
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
62 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2020-24949Proof of concept | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to thephp-fusion · php-fusion | High8.8 | — | 67.5% | Sep 3, 2020 |
45Plan | CVE-2010-4931Proof of concept | Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .php-fusion · php-fusion · CWE-22 | Critical10.0 | — | 15.6% | Oct 9, 2011 |
40Plan | CVE-2019-12099Proof of concept | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_php-fusion · php-fusion · CWE-434 | High8.8 | — | 17.2% | May 14, 2019 |
38Monitor | CVE-2020-23754No exploit | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arphp-fusion · phpfusion · CWE-79 | Critical9.6 | — | 1.6% | Nov 2, 2021 |
36Monitor | CVE-2020-12461No exploit | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism.php-fusion · php-fusion · CWE-89 | High8.8 | — | 1.7% | Apr 29, 2020 |
35Monitor | CVE-2023-2453No exploit | Local file Inclusion (LFI) in Forum Infusion via Directory Traversalphp-fusion · phpfusion · CWE-829 | High8.8 | — | 0.9% | Sep 5, 2023 |
35Monitor | CVE-2022-3152No exploit | Unverified Password Change in phpfusion/phpfusionphp-fusion · phpfusion · CWE-620 | High8.8 | — | 0.9% | Sep 7, 2022 |
34Monitor | CVE-2020-37137No exploit | PHP-Fusion 9.03.50 - 'panels.php' Eval Injectionphp-fusion · phpfusion · CWE-95 | High8.6 | — | 0.6% | Feb 5, 2026 |
32Monitor | CVE-2021-3172No exploit | An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling fephp-fusion · php-fusion · CWE-732 | High8.1 | — | 0.6% | Feb 17, 2023 |
31Monitor | CVE-2007-5187Proof of concept | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remphp-fusion · expanded calendar module · CWE-89 | High7.5 | — | 4.2% | Oct 3, 2007 |
31Monitor | CVE-2008-5197Proof of concept | SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameterphp-fusion · php-fusion · CWE-89 | High7.5 | — | 4.1% | Nov 21, 2008 |
31Monitor | CVE-2013-1803Proof of concept | Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) ordphp-fusion · php-fusion · CWE-89 | High7.5 | — | 4.0% | May 5, 2014 |
31Monitor | CVE-2013-7375Proof of concept | SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execphp-fusion · php-fusion · CWE-89 | High7.5 | — | 3.6% | May 5, 2014 |
31Monitor | CVE-2014-8596Proof of concept | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) php-fusion · php-fusion · CWE-89 | High7.5 | — | 3.3% | Nov 17, 2014 |
30Monitor | CVE-2010-4791Proof of concept | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) momarcusg · mg user fotoalbum panel · CWE-89 | High7.5 | — | 1.2% | Apr 26, 2011 |
30Monitor | CVE-2009-0832Proof of concept | SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands vphp-fusion · php-fusion · CWE-89 | High7.5 | — | 1.1% | Mar 5, 2009 |
30Monitor | CVE-2008-4527Proof of concept | SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQphp-fusion · recepies module · CWE-89 | High7.5 | — | 1.0% | Oct 9, 2008 |
30Monitor | CVE-2008-5733Proof of concept | SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQphp-fusion · team impact ti blog system module · CWE-89 | High7.5 | — | 1.0% | Dec 26, 2008 |
30Monitor | CVE-2009-3119Proof of concept | SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrphp-fusion · php-fusion · CWE-89 | High7.5 | — | 1.0% | Sep 9, 2009 |
30Monitor | CVE-2008-5074Proof of concept | SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL cophp-fusion · freshlinks module · CWE-89 | High7.5 | — | 1.0% | Nov 14, 2008 |
30Monitor | CVE-2008-4521Proof of concept | SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion php-fusion · world of warcraft tracker infusion module · CWE-89 | High7.5 | — | 1.0% | Oct 9, 2008 |
30Monitor | CVE-2008-5196Proof of concept | SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute php-fusion · php-fusion · CWE-89 | High7.5 | — | 1.0% | Nov 21, 2008 |
30Monitor | CVE-2008-5946Proof of concept | SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parphp-fusion · php-fusion · CWE-89 | High7.5 | — | 1.0% | Jan 22, 2009 |
30Monitor | CVE-2009-4889Proof of concept | SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary Sphp-fusion · php-fusion · CWE-89 | High7.5 | — | 1.0% | Jun 11, 2010 |
29Monitor | CVE-2021-40189No exploit | PHPFusion 9.03.110 is affected by a remote code execution vulnerability.php-fusion · phpfusion · CWE-434 | High7.2 | — | 1.8% | Oct 11, 2021 |
- CVE-2020-2494955Plan
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the
HighCVSS 8.8Proof of conceptEPSS 68%php-fusion · php-fusionSep 3, 2020
- CVE-2010-493145Plan
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .
CriticalCVSS 10.0Proof of conceptEPSS 16%php-fusion · php-fusionOct 9, 2011
- CVE-2019-1209940Plan
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_
HighCVSS 8.8Proof of conceptEPSS 17%php-fusion · php-fusionMay 14, 2019
- CVE-2020-2375438Monitor
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute ar
CriticalCVSS 9.6No exploitEPSS 2%php-fusion · phpfusionNov 2, 2021
- CVE-2020-1246136Monitor
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism.
HighCVSS 8.8No exploitEPSS 2%php-fusion · php-fusionApr 29, 2020
- CVE-2023-245335Monitor
Local file Inclusion (LFI) in Forum Infusion via Directory Traversal
HighCVSS 8.8No exploitEPSS 1%php-fusion · phpfusionSep 5, 2023
- CVE-2022-315235Monitor
Unverified Password Change in phpfusion/phpfusion
HighCVSS 8.8No exploitEPSS 1%php-fusion · phpfusionSep 7, 2022
- CVE-2020-3713734Monitor
PHP-Fusion 9.03.50 - 'panels.php' Eval Injection
HighCVSS 8.6No exploitEPSS 1%php-fusion · phpfusionFeb 5, 2026
- CVE-2021-317232Monitor
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling fe
HighCVSS 8.1No exploitEPSS 1%php-fusion · php-fusionFeb 17, 2023
- CVE-2007-518731Monitor
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows rem
HighCVSS 7.5Proof of conceptEPSS 4%php-fusion · expanded calendar moduleOct 3, 2007
- CVE-2008-519731Monitor
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter
HighCVSS 7.5Proof of conceptEPSS 4%php-fusion · php-fusionNov 21, 2008
- CVE-2013-180331Monitor
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) ord
HighCVSS 7.5Proof of conceptEPSS 4%php-fusion · php-fusionMay 5, 2014
- CVE-2013-737531Monitor
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to exec
HighCVSS 7.5Proof of conceptEPSS 4%php-fusion · php-fusionMay 5, 2014
- CVE-2014-859631Monitor
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1)
HighCVSS 7.5Proof of conceptEPSS 3%php-fusion · php-fusionNov 17, 2014
- CVE-2010-479130Monitor
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) mo
HighCVSS 7.5Proof of conceptEPSS 1%marcusg · mg user fotoalbum panelApr 26, 2011
- CVE-2009-083230Monitor
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · php-fusionMar 5, 2009
- CVE-2008-452730Monitor
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQ
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · recepies moduleOct 9, 2008
- CVE-2008-573330Monitor
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQ
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · team impact ti blog system moduleDec 26, 2008
- CVE-2009-311930Monitor
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitr
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · php-fusionSep 9, 2009
- CVE-2008-507430Monitor
SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL co
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · freshlinks moduleNov 14, 2008
- CVE-2008-452130Monitor
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · world of warcraft tracker infusion moduleOct 9, 2008
- CVE-2008-519630Monitor
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · php-fusionNov 21, 2008
- CVE-2008-594630Monitor
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id par
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · php-fusionJan 22, 2009
- CVE-2009-488930Monitor
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary S
HighCVSS 7.5Proof of conceptEPSS 1%php-fusion · php-fusionJun 11, 2010
- CVE-2021-4018929Monitor
PHPFusion 9.03.110 is affected by a remote code execution vulnerability.
HighCVSS 7.2No exploitEPSS 2%php-fusion · phpfusionOct 11, 2021