Glfusion is a content management system with a modest vulnerability footprint concentrated entirely in its core product. The recurring weaknesses—cross-site scripting, SQL injection, authorization bypass, CSRF, and improper authentication—are characteristic of web applications handling user input and session management, and vulnerabilities of these classes frequently acquire public exploit code. Vulnerabilities affecting this vendor skew toward serious outcomes; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Glfusion over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4796HIGH Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execut | Apr 22, 2010 | 7.5 | 34 | NO | YES |
CVE-2021-44949CRITICAL glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. | Dec 14, 2021 | 9.8 | 31 | NO | NO |
CVE-2009-1282HIGH SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie par | Apr 9, 2009 | 7.5 | 29 | NO | YES |
CVE-2021-44935CRITICAL glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction. | Dec 14, 2021 | 9.1 | 27 | NO | NO |
CVE-2009-1283MEDIUM glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and u | Apr 9, 2009 | 6.8 | 26 | NO | YES |
CVE-2013-1466MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the (1) subject parameter to prof | Feb 5, 2014 | 4.3 | 22 | NO | YES |
CVE-2021-45843MEDIUM glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute | Sep 29, 2022 | 6.1 | 21 | NO | NO |
CVE-2009-1281MEDIUM Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 9, 2009 | 4.3 | 21 | NO | YES |
CVE-2021-44937MEDIUM glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to | Dec 14, 2021 | 5.3 | 19 | NO | NO |
Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbit | Feb 11, 2009 | 2.6 | 18 | NO | YES |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Glfusion.
Media articles that mention a CVE ID that affects a product developed by Glfusion — matched by CVE ID, not by vendor name.