PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsNone
PrivilegesLow
User InteractionPassive
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityLow
IntegrityLow
AvailabilityNone
Subsequent System
ConfidentialityLow
IntegrityLow
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | cve.org | initial, patch: Unavailable | 1.2 |
Affected Software
| Vendor | Product | Version |
|---|
| PHP-Fusion | PHP-Fusion | 9.03.50 |
| php-fusion | phpfusion | 9.03.50 |
Published: 2026-02-05