Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.80%—Php-fusion12/8/202017/6/2026
PHP-Fusion 9.03 allows XSS on the preview page.
ModificadaMedia (5.4)0.55%—Php-fusion12/8/202017/6/2026
PHP-Fusion 9.03 allows XSS via the error_log file.
ModificadaMedia (4.8)0.54%—Php-fusion24/6/202017/6/2026
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
ModificadaAlta (7.2)1.7%—Php-fusion22/6/202017/6/2026
A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,
ModificadaMedia (5.4)0.66%—Php-fusion8/5/202017/6/2026
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.
ModificadaMedia (6.1)0.92%—Php-fusion7/5/202017/6/2026
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
ModificadaMedia (5.4)2.9%💥 ExploitPhp-fusion7/5/202017/6/2026
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php
ModificadaAlta (8.8)1.7%—Php-fusion29/4/202017/6/2026
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in…
ModificadaMedia (5.4)0.58%—Php-fusion28/4/202017/6/2026
An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.
ModificadaAlta (8.8)17%💥 ExploitPhp-fusion14/5/201917/6/2026
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.
ModificadaMedia (5.4)0.98%—Php-fusion25/9/201717/6/2026
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
ModificadaAlta (7.5)3.3%💥 ExploitPhp-fusion17/11/201417/6/2026
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.
ModificadaAlta (7.5)3.6%💥 ExploitPhp-fusion5/5/201417/6/2026
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.
ModificadaAlta (7.5)4.0%💥 ExploitPhp-fusion5/5/201416/6/2026
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated users with certain permissions to execute arbitrary SQL commands via a (2) parameter name starting with "delete_attach_"…
ModificadaMedia (5)7.6%💥 ExploitPhp-fusion30/4/201416/6/2026
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.
ModificadaMedia (6.5)7.8%💥 ExploitPhp-fusion30/4/201416/6/2026
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to…
ModificadaMedia (4.3)4.4%💥 ExploitPhp-fusion29/4/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (2) user_list or…
ModificadaMedia (4.3)1.6%💥 ExploitPhp-fusion26/11/201216/6/2026
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
ModificadaAlta (10)16%💥 ExploitPhp-fusion9/10/201116/6/2026
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party
ModificadaMedia (4.3)1.1%—Php-fusion7/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion 6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6)0.94%💥 ExploitPhp-fusion Members CV Module5/3/200916/6/2026
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.
ModificadaAlta (7.5)0.96%💥 ExploitPhp-fusion22/1/200916/6/2026
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
ModificadaAlta (7.5)1.00%💥 ExploitPhp-fusion Team Impact TI Blog System Module26/12/200816/6/2026
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)2.9%💥 ExploitPhp-fusion5/12/200816/6/2026
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.
ModificadaAlta (7.5)4.1%💥 ExploitPhp-fusion21/11/200816/6/2026
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.
Orbitaley — Vulnerabilidades