VendorsPHP-Fusionphpfusionall versions
Vulnerabilities

PHP-Fusion Phpfusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2020-37137
PHP-Fusion 9.03.50 - 'panels.php' Eval Injection
Published 2026-02-05 · Analyzed
9.8EPSS 0.006
CVE-2020-23754
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
Published 2021-11-02 · Modified
9.6EPSS 0.016
CVE-2022-3152
Unverified Password Change in phpfusion/phpfusion
Published 2022-09-07 · Modified
9.6EPSS 0.009
CVE-2023-2453
Local file Inclusion (LFI) in Forum Infusion via Directory Traversal
Published 2023-09-05 · Modified
8.8EPSS 0.009
CVE-2021-40189
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.
Published 2021-10-11 · Modified
7.2EPSS 0.018
CVE-2021-40188
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.
Published 2021-10-11 · Modified
7.2EPSS 0.013
CVE-2014-8597
A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.
Published 2022-02-17 · Modified
6.1EPSS 0.008
CVE-2021-28280
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
Published 2021-04-29 · Modified
6.1EPSS 0.007
CVE-2021-40541
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
Published 2021-10-11 · Modified
6.1EPSS 0.006
CVE-2023-53928
PHPFusion 9.10.30 Stored Cross-Site Scripting via File Manager Upload
Published 2025-12-17 · Analyzed
6.1EPSS 0.003
CVE-2020-37152
PHP-Fusion 9.03.50 panels.php - Cross-Site Scripting (XSS)
Published 2026-02-05 · Analyzed
6.1EPSS 0.003
CVE-2023-4480
Arbitrary File Read in Fusion File Manager
Published 2023-09-05 · Modified
5.5EPSS 0.007
CVE-2020-35687
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
Published 2021-01-13 · Modified
4.31 PoCEPSS 0.014