Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php-fusion phpfusion
|
|
| CPEs | cpe:2.3:a:php-fusion:phpfusion:9.03.50:*:*:*:*:*:*:* | |
| Vendors & Products |
Php-fusion phpfusion
|
|
| Metrics |
cvssV3_1
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php-fusion
Php-fusion php-fusion |
|
| Vendors & Products |
Php-fusion
Php-fusion php-fusion |
Thu, 05 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site. | |
| Title | PHP-Fusion 9.03.50 panels.php - Cross-Site Scripting (XSS) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-05T16:34:35.394Z
Reserved: 2026-02-03T16:27:45.309Z
Link: CVE-2020-37152
Updated: 2026-02-05T16:34:30.432Z
Status : Analyzed
Published: 2026-02-05T17:16:10.897
Modified: 2026-02-09T22:09:43.157
Link: CVE-2020-37152
No data.
OpenCVE Enrichment
Updated: 2026-02-06T12:05:16Z