Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:php-fusion:phpfusion:*:*:*:*:*:*:*:* |
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php-fusion
Php-fusion phpfusion |
|
| Vendors & Products |
Php-fusion
Php-fusion phpfusion |
Fri, 30 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers. | |
| Title | PHPFusion 9.03.50 - Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T02:06:45.710Z
Reserved: 2026-01-27T15:47:08.000Z
Link: CVE-2020-36996
Updated: 2026-01-30T16:30:22.968Z
Status : Deferred
Published: 2026-01-30T17:16:10.323
Modified: 2026-04-15T00:35:42.020
Link: CVE-2020-36996
No data.
OpenCVE Enrichment
Updated: 2026-02-02T09:27:43Z