Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

fogproject — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in fogproject, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the open-source imaging solution fogproject, categorized by Common Weakness Enumeration (CWE) classifications. It collects publicly disclosed security flaws affecting fogproject versions, spanning from the initial release through the most recent updates available in public vulnerability databases. This resource allows administrators and security researchers to track vendor advisories related to fogproject, understand the specific nature of each weakness class, and review the product’s complete vulnerability history over time. By centralizing this information, the page provides a clear view of the security posture associated with the software, highlighting areas where patches or configuration changes may be necessary. The data is sourced from established vulnerability tracking platforms and is presented to facilitate risk assessment and remediation planning. Users can explore how different versions of fogproject have been affected by various types of security issues, including injection flaws, privilege escalation risks, and information disclosure errors. This structured approach helps identify patterns in vulnerability reporting and supports informed decision-making regarding software maintenance and upgrade schedules. The focus remains strictly on factual reporting of identified weaknesses without speculation or recommendation.

Vendor: FOGProject

CVE ID Title CVSS Severity Published
CVE-2026-47689 FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab CWE-79 4.6 Medium 2026-07-21
CVE-2026-47688 FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules CWE-862 8.2 High 2026-07-21
CVE-2026-47687 FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint CWE-79 7.3 High 2026-07-21
CVE-2026-47685 FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page CWE-79 7.3 High 2026-07-21
CVE-2026-33739 FOG has Stored XSS in Multiple Management Pages CWE-79 5.7 Medium 2026-03-27
CVE-2026-24138 FOG vulnerable to unauthenticated SSRF via `/fog/service/getversion.php` CWE-918 7.5 High 2026-01-23
CVE-2025-58443 FOG's authentication bypass leads to full SQL DB dump CWE-306 9.8AI Critical AI 2025-09-06
CVE-2024-42349 FOG has a Log Information Disclosure CWE-532 5.3 Medium 2024-08-02
CVE-2024-42348 FOG leaks sensitive information (AD domain, username and password) CWE-77 9.3 Critical 2024-08-02
CVE-2024-41954 FOG Weak file permissions CWE-732 5.3 Medium 2024-07-31
CVE-2024-41108 FOG Sensitive Information Disclosure CWE-200 7.5 High 2024-07-31
CVE-2024-40645 FOG Authenticated File Upload RCE CWE-434 8.8 High 2024-07-31
CVE-2024-39916 NFS server misconfiguration allows file access outside the exported directory CWE-453 6.4 Medium 2024-07-12
CVE-2024-39914 FOG has a command injection in /fog/management/export.php?filename= CWE-77 9.8 Critical 2024-07-12
CVE-2023-46237 FOG path traversal via unauthenticated endpoint CWE-22 5.8 Medium 2023-10-31
CVE-2023-46236 FOG SSRF via unauthenticated endpoint(s) CWE-918 8.6 High 2023-10-31
CVE-2023-46235 FOG stored XSS on log screen via unsanitized request logging CWE-79 5.4 Medium 2023-10-31

All 17 known CVE vulnerabilities affecting fogproject with full Chinese analysis, references, and POCs where available.