CVE-2020-36996: PHP-Fusion Phpfusion
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.
Affected products
- PHP-Fusion Phpfusion: up to and including 9.03.50
Published 2026-01-30. Last modified 2026-06-17.