Glfusion

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-45843

    glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response.

    Last Modified: Nov 21, 2024
    Published: Dec 27, 2021

    CVE-2021-44942

    glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021

    CVE-2021-44949

    glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021

    CVE-2021-44937

    glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021

    CVE-2021-44935

    glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021
    Items Per Page
    Glfusion Vulnerabilities & Security CVEs | CVE-DB