PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/48299 | Not Applicable |
| https://www.php-fusion.co.uk/ | Product |
| https://www.vulncheck.com/advisories/php-fusion-panelsphp-cross-site-scripting-xss | Broken Link |
Configurations
History
09 Feb 2026, 22:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:php-fusion:phpfusion:9.03.50:*:*:*:*:*:*:* | |
| First Time |
Php-fusion
Php-fusion phpfusion |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://www.exploit-db.com/exploits/48299 - Not Applicable | |
| References | () https://www.php-fusion.co.uk/ - Product | |
| References | () https://www.vulncheck.com/advisories/php-fusion-panelsphp-cross-site-scripting-xss - Broken Link |
05 Feb 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-05 17:16
Updated : 2026-02-09 22:09
NVD link : CVE-2020-37152
Mitre link : CVE-2020-37152
CVE.ORG link : CVE-2020-37152
JSON object : View
Products Affected
php-fusion
- phpfusion
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
