VendorsFOGProjectfogprojectall versions
Vulnerabilities

FOGProject Fogproject

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2025-58443
FOG's authentication bypass leads to full SQL DB dump
Published 2025-09-06 · Analyzed
9.9EPSS 0.185
CVE-2024-39914
FOG has a command injection in /fog/management/export.php?filename=
Published 2024-07-12 · Analyzed
9.8EPSS 0.232
CVE-2024-42348
FOG leaks sensitive information (AD domain, username and password)
Published 2024-08-02 · Analyzed
9.3EPSS 0.006
CVE-2021-32243
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
Published 2021-06-16 · Modified
8.8EPSS 0.011
CVE-2024-40645
FOG Authenticated File Upload RCE
Published 2024-07-31 · Analyzed
8.8EPSS 0.010
CVE-2026-47687
FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint
Published 2026-07-21 · Analyzed
8.7EPSS 0.004
CVE-2026-47685
FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page
Published 2026-07-21 · Analyzed
8.7EPSS 0.004
CVE-2023-46236
FOG SSRF via unauthenticated endpoint(s)
Published 2023-10-31 · Modified
8.6EPSS 0.005
CVE-2026-47688
FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules
Published 2026-07-21 · Analyzed
8.2EPSS 0.003
CVE-2024-41954
FOG Weak file permissions
Published 2024-07-31 · Analyzed
7.8EPSS 0.003
CVE-2024-34477
configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In order to exploit the vulnerability, someone needs to mount an NFS share in order to add an executable file as root. In addition, the SUID bit must be added to this file.
Published 2024-05-27 · Analyzed
7.8EPSS 0.003
CVE-2024-41108
FOG Sensitive Information Disclosure
Published 2024-07-31 · Analyzed
7.5EPSS 0.006
CVE-2024-39916
NFS server misconfiguration allows file access outside the exported directory
Published 2024-07-12 · Modified
6.4EPSS 0.003
CVE-2023-46235
FOG stored XSS on log screen via unsanitized request logging
Published 2023-10-31 · Modified
6.1EPSS 0.003
CVE-2023-46237
FOG path traversal via unauthenticated endpoint
Published 2023-10-31 · Modified
5.8EPSS 0.005
CVE-2026-33739
FOG has Stored XSS in Multiple Management Pages
Published 2026-03-27 · Analyzed
5.7EPSS 0.003
CVE-2024-42349
FOG has a Log Information Disclosure
Published 2024-08-02 · Analyzed
5.3EPSS 0.006
CVE-2026-47689
FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab
Published 2026-07-21 · Analyzed
5.2EPSS 0.003