Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2020-23702

Disclosure Date: July 07, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.
Attacker Value
Unknown

CVE-2020-23185

Disclosure Date: July 02, 2021 (last updated November 28, 2024)
A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2020-23181

Disclosure Date: July 02, 2021 (last updated November 28, 2024)
A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field.
Attacker Value
Unknown

CVE-2020-23182

Disclosure Date: July 02, 2021 (last updated November 28, 2024)
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.
Attacker Value
Unknown

CVE-2020-23184

Disclosure Date: July 02, 2021 (last updated November 28, 2024)
A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.
Attacker Value
Unknown

CVE-2020-23658

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.
Attacker Value
Unknown

CVE-2020-15041

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.