CVE-2020-12718: PHP-Fusion

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.

Affected products

Published 2020-05-08. Last modified 2026-06-17.