Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php-fusion phpfusion
|
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:php-fusion:phpfusion:9.03.50:*:*:*:*:*:*:* | |
| Vendors & Products |
Php-fusion phpfusion
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php-fusion
Php-fusion php-fusion |
|
| Vendors & Products |
Php-fusion
Php-fusion php-fusion |
Thu, 05 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code. | |
| Title | PHP-Fusion 9.03.50 - 'panels.php' Eval Injection | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-05T20:37:15.390Z
Reserved: 2026-02-03T16:27:45.307Z
Link: CVE-2020-37137
Updated: 2026-02-05T20:37:04.685Z
Status : Analyzed
Published: 2026-02-05T17:16:09.003
Modified: 2026-02-09T22:10:05.763
Link: CVE-2020-37137
No data.
OpenCVE Enrichment
Updated: 2026-02-06T12:05:35Z