php-fusion CVE Vulnerabilities & Metrics

Focus on php-fusion vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About php-fusion Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with php-fusion. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total php-fusion CVEs: 32
Earliest CVE date: 04 Jul 2007, 16:30 UTC
Latest CVE date: 05 Sep 2023, 15:15 UTC

Latest CVE reference: CVE-2023-4480

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical php-fusion CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.12

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 17
4.0-6.9 23
7.0-8.9 10
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS php-fusion CVEs

These are the five CVEs with the highest CVSS scores for php-fusion, sorted by severity first and recency.

All CVEs for php-fusion

CVE-2023-4480 php-fusion vulnerability CVSS: 0 05 Sep 2023, 15:15 UTC

Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the privileges of the running process. Additionally, they may write files to arbitrary locations, provided the files pass the application’s mime-type and file extension validation. 

CVE-2023-2453 php-fusion vulnerability CVSS: 0 05 Sep 2023, 15:15 UTC

There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a ‘.php’ file payload.

CVE-2021-3172 php-fusion vulnerability CVSS: 0 17 Feb 2023, 18:15 UTC

An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.

CVE-2022-3152 php-fusion vulnerability CVSS: 0 07 Sep 2022, 15:15 UTC

Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.

CVE-2014-8597 php-fusion vulnerability CVSS: 4.3 17 Feb 2022, 20:15 UTC

A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

CVE-2020-23754 php-fusion vulnerability CVSS: 6.8 02 Nov 2021, 18:15 UTC

Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.

CVE-2021-40189 php-fusion vulnerability CVSS: 6.5 11 Oct 2021, 19:15 UTC

PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.

CVE-2021-40188 php-fusion vulnerability CVSS: 6.5 11 Oct 2021, 19:15 UTC

PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.

CVE-2021-40541 php-fusion vulnerability CVSS: 4.3 11 Oct 2021, 14:15 UTC

PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.

CVE-2020-23702 php-fusion vulnerability CVSS: 3.5 07 Jul 2021, 19:15 UTC

Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.

CVE-2020-23185 php-fusion vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2020-23184 php-fusion vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.

CVE-2020-23182 php-fusion vulnerability CVSS: 4.9 02 Jul 2021, 18:15 UTC

The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.

CVE-2020-23181 php-fusion vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field.

CVE-2020-23179 php-fusion vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.

CVE-2020-23178 php-fusion vulnerability CVSS: 5.5 02 Jul 2021, 18:15 UTC

An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.

CVE-2021-28280 php-fusion vulnerability CVSS: 4.3 29 Apr 2021, 15:15 UTC

CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML

CVE-2020-35687 php-fusion vulnerability CVSS: 4.3 13 Jan 2021, 17:15 UTC

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

CVE-2020-35952 php-fusion vulnerability CVSS: 4.0 03 Jan 2021, 04:15 UTC

login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.

CVE-2020-24949 php-fusion vulnerability CVSS: 9.0 03 Sep 2020, 14:15 UTC

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

CVE-2020-23658 php-fusion vulnerability CVSS: 3.5 26 Aug 2020, 18:15 UTC

PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.

CVE-2020-17450 php-fusion vulnerability CVSS: 4.3 12 Aug 2020, 22:15 UTC

PHP-Fusion 9.03 allows XSS on the preview page.

CVE-2020-17449 php-fusion vulnerability CVSS: 3.5 12 Aug 2020, 22:15 UTC

PHP-Fusion 9.03 allows XSS via the error_log file.

CVE-2020-15041 php-fusion vulnerability CVSS: 3.5 24 Jun 2020, 21:15 UTC

PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.

CVE-2020-14960 php-fusion vulnerability CVSS: 6.5 22 Jun 2020, 00:15 UTC

A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,

CVE-2020-12718 php-fusion vulnerability CVSS: 3.5 08 May 2020, 00:15 UTC

In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.

CVE-2020-12708 php-fusion vulnerability CVSS: 4.3 07 May 2020, 20:15 UTC

Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.

CVE-2020-12706 php-fusion vulnerability CVSS: 3.5 07 May 2020, 20:15 UTC

Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php

CVE-2020-12461 php-fusion vulnerability CVSS: 6.5 29 Apr 2020, 17:15 UTC

PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query.

CVE-2020-12438 php-fusion vulnerability CVSS: 3.5 28 Apr 2020, 21:15 UTC

An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.

CVE-2019-12099 php-fusion vulnerability CVSS: 9.0 14 May 2019, 21:29 UTC

In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.

CVE-2015-8375 php-fusion vulnerability CVSS: 3.5 25 Sep 2017, 21:29 UTC

Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

CVE-2014-8596 php-fusion vulnerability CVSS: 7.5 17 Nov 2014, 16:59 UTC

Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.

CVE-2013-7375 php-fusion vulnerability CVSS: 7.5 05 May 2014, 17:06 UTC

SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.

CVE-2013-1803 php-fusion vulnerability CVSS: 7.5 05 May 2014, 17:06 UTC

Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated users with certain permissions to execute arbitrary SQL commands via a (2) parameter name starting with "delete_attach_" in an edit action to forum/postedit.php; the (3) poll_opts[] parameter in a newthread action to forum/postnewthread.php; the (4) pm_email_notify, (5) pm_save_sent, (6) pm_inbox, (7) pm_sentbox, or (8) pm_savebox parameter to administration/settings_messages.php; the (9) thumb_compression, (10) photo_watermark_text_color1, (11) photo_watermark_text_color2, or (12) photo_watermark_text_color3 parameter to administration/settings_photo.php; the (13) enable parameter to administration/bbcodes.php; the (14) news_image, (15) news_image_t1, or (16) news_image_t2 parameter to administration/news.php; the (17) news_id parameter in an edit action to administration/news.php; or the (18) article_id parameter in an edit action to administration/articles.php. NOTE: the user ID cookie issue in Authenticate.class.php is already covered by CVE-2013-7375.

CVE-2013-1807 php-fusion vulnerability CVSS: 5.0 30 Apr 2014, 23:58 UTC

PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

CVE-2013-1806 php-fusion vulnerability CVSS: 6.5 30 Apr 2014, 23:58 UTC

Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php.

CVE-2013-1804 php-fusion vulnerability CVSS: 4.3 29 Apr 2014, 20:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (2) user_list or (3) user_types parameter to messages.php; (4) message parameter to infusions/shoutbox_panel/shoutbox_admin.php; (5) message parameter to administration/news.php; (6) panel_list parameter to administration/panel_editor.php; (7) HTTP User Agent string to administration/phpinfo.php; (8) "__BBCODE__" parameter to administration/bbcodes.php; errorMessage parameter to (9) article_cats.php, (10) download_cats.php, (11) news_cats.php, or (12) weblink_cats.php in administration/, when error is 3; or (13) body or (14) body2 parameter to administration/articles.php.

CVE-2012-6043 php-fusion vulnerability CVSS: 4.3 26 Nov 2012, 22:55 UTC

Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

CVE-2010-4931 php-fusion vulnerability CVSS: 10.0 09 Oct 2011, 10:55 UTC

Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party

CVE-2008-6850 php-fusion vulnerability CVSS: 4.3 07 Jul 2009, 19:00 UTC

Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion 6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-0831 php-fusion vulnerability CVSS: 6.0 05 Mar 2009, 20:30 UTC

SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.

CVE-2008-5946 php-fusion vulnerability CVSS: 7.5 22 Jan 2009, 11:30 UTC

SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

CVE-2008-5733 php-fusion vulnerability CVSS: 7.5 26 Dec 2008, 17:30 UTC

SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2008-5335 php-fusion vulnerability CVSS: 6.8 05 Dec 2008, 01:30 UTC

SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.

CVE-2008-5197 php-fusion vulnerability CVSS: 7.5 21 Nov 2008, 17:30 UTC

SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.

CVE-2008-5074 php-fusion vulnerability CVSS: 7.5 14 Nov 2008, 18:07 UTC

SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

CVE-2008-4527 php-fusion vulnerability CVSS: 7.5 09 Oct 2008, 18:14 UTC

SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action. NOTE: some of these details are obtained from third party information.

CVE-2008-4521 php-fusion vulnerability CVSS: 7.5 09 Oct 2008, 18:14 UTC

SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.

CVE-2008-2227 php-fusion vulnerability CVSS: 6.8 14 May 2008, 18:20 UTC

Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2008-1918 php-fusion vulnerability CVSS: 6.0 23 Apr 2008, 13:05 UTC

SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.

CVE-2007-5187 php-fusion vulnerability CVSS: 7.5 03 Oct 2007, 14:17 UTC

SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter.

CVE-2007-3559 php-fusion vulnerability CVSS: 3.5 04 Jul 2007, 16:30 UTC

Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant.