Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-34560

    A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.

    Last Modified: Apr 22, 2025
    Published: Apr 22, 2024

    CVE-2022-34562

    A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the status box.

    Last Modified: Apr 22, 2025
    Published: Apr 22, 2024

    CVE-2022-34561

    A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the video description parameter.

    Last Modified: Apr 22, 2025
    Published: Apr 22, 2024

    CVE-2023-46817

    An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

    Last Modified: Nov 21, 2024
    Published: Nov 03, 2023

    CVE-2013-7195

    PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specifies the ID for the publication.

    Last Modified: Apr 12, 2025
    Published: Apr 18, 2014
    Items Per Page
    Phpfox Vulnerabilities & Security CVEs | CVE-DB