Fogproject is a modestly represented systems management and imaging platform deployed in IT environments for system provisioning and bare-metal recovery. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit code; the exposure recurs across its core product line through weakness classes characteristic of web-facing administrative tools—including cross-site scripting, command injection, unrestricted file uploads, privilege escalation, and information disclosure. Defenders should treat updates to this vendor's offerings as high-priority, particularly where internet-exposed or trusted network instances are in use; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fogproject over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-39914CRITICAL FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the | Jul 12, 2024 | 9.8 | 53 | NO | YES |
CVE-2025-58443CRITICAL FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible fo | Sep 6, 2025 | 9.1 | 50 | NO | YES |
CVE-2021-32243HIGH FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated). | Jun 16, 2021 | 8.8 | 26 | NO | NO |
CVE-2024-40645HIGH FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproje | Jul 31, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-42348HIGH FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixe | Aug 2, 2024 | 8.6 | 24 | NO | NO |
CVE-2024-41954HIGH FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by | Jul 31, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-34477HIGH configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In ord | May 27, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-41108MEDIUM FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is requi | Jul 31, 2024 | 5.9 | 19 | NO | NO |
CVE-2024-39916MEDIUM FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer | Jul 12, 2024 | 6.4 | 19 | NO | NO |
CVE-2023-46236HIGH FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthent | Oct 31, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fogproject.
Media articles that mention a CVE ID that affects a product developed by Fogproject — matched by CVE ID, not by vendor name.