Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Php-fusion | 12/8/2020 | 17/6/2026 | PHP-Fusion 9.03 allows XSS on the preview page. | |
| Modificada | Media (5.4) | 0.55% | — | Php-fusion | 12/8/2020 | 17/6/2026 | PHP-Fusion 9.03 allows XSS via the error_log file. | |
| Modificada | Media (4.8) | 0.54% | — | Php-fusion | 24/6/2020 | 17/6/2026 | PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field. | |
| Modificada | Alta (7.2) | 1.7% | — | Php-fusion | 22/6/2020 | 17/6/2026 | A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter, | |
| Modificada | Media (5.4) | 0.66% | — | Php-fusion | 8/5/2020 | 17/6/2026 | In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle. | |
| Modificada | Media (6.1) | 0.92% | — | Php-fusion | 7/5/2020 | 17/6/2026 | Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043. | |
| Modificada | Media (5.4) | 2.9% | 💥 Exploit | Php-fusion | 7/5/2020 | 17/6/2026 | Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php | |
| Modificada | Alta (8.8) | 1.7% | — | Php-fusion | 29/4/2020 | 17/6/2026 | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in… | |
| Modificada | Media (5.4) | 0.58% | — | Php-fusion | 28/4/2020 | 17/6/2026 | An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Php-fusion | 14/5/2019 | 17/6/2026 | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload. | |
| Modificada | Media (5.4) | 0.98% | — | Php-fusion | 25/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in PHP-Fusion 9. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Php-fusion | 17/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Php-fusion | 5/5/2014 | 17/6/2026 | SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Php-fusion | 5/5/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated users with certain permissions to execute arbitrary SQL commands via a (2) parameter name starting with "delete_attach_"… | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Php-fusion | 30/4/2014 | 16/6/2026 | PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/. | |
| Modificada | Media (6.5) | 7.8% | 💥 Exploit | Php-fusion | 30/4/2014 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to… | |
| Modificada | Media (4.3) | 4.4% | 💥 Exploit | Php-fusion | 29/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (2) user_list or… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Php-fusion | 26/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Php-fusion | 9/10/2011 | 16/6/2026 | Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party | |
| Modificada | Media (4.3) | 1.1% | — | Php-fusion | 7/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion 6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6) | 0.94% | 💥 Exploit | Php-fusion Members CV Module | 5/3/2009 | 16/6/2026 | SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Php-fusion | 22/1/2009 | 16/6/2026 | SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Php-fusion Team Impact TI Blog System Module | 26/12/2008 | 16/6/2026 | SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Php-fusion | 5/12/2008 | 16/6/2026 | SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459. | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Php-fusion | 21/11/2008 | 16/6/2026 | SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action. |