CVE-2020-36996

MEDIUM

PHPFusion 9.03.50 - XSS

Title source: llm
STIX 2.1

Description

PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.

Exploits (1)

exploitdb WRITEUP
by coiffeur · textwebappsphp
https://www.exploit-db.com/exploits/48497

Scores

CVSS v3 6.4
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Jan 30, 2026
Tracked Since Feb 18, 2026