FusionForge is a project collaboration and source-code management platform whose vulnerability profile centers on its core application and reflects common challenges in web-based development tools, specifically around information disclosure, input handling, file upload validation, and symbolic-link traversal in file operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fusionforge over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0850HIGH The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary Git repository. | Jun 2, 2015 | 10.0 | 30 | NO | NO |
CVE-2014-0468CRITICAL Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that
the users would have uploaded in their raw SCM repositories (SVN, G | Jun 26, 2025 | 9.8 | 29 | NO | NO |
CVE-2014-6275MEDIUM FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server th | Jan 2, 2020 | 5.9 | 21 | NO | NO |
CVE-2013-1423MEDIUM (1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-specific/ssh_dump_update.pl, (6) deb | Mar 14, 2013 | 6.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fusionforge.
Media articles that mention a CVE ID that affects a product developed by Fusionforge — matched by CVE ID, not by vendor name.