Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FOGProject — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting FOGProject. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FOGProject is an open-source computer imaging solution primarily used for network-based deployment of operating systems across multiple machines. Historically, the project has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation flaws, with 13 CVEs documented to date. Security researchers have identified authentication bypass issues and insecure default configurations in various versions. While no major public security incidents have been widely reported, the persistent presence of multiple CVEs suggests ongoing challenges in secure coding practices, particularly in web interface components and deployment mechanisms.

Found 17 results / 17 Clear Filters
Top products by FOGProject: fogproject
CVE ID Title CVSS Severity Published
CVE-2026-47689 FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab — fogproject CWE-79 4.6 Medium 2026-07-21
CVE-2026-47688 FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules — fogproject CWE-862 8.2 High 2026-07-21
CVE-2026-47687 FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint — fogproject CWE-79 7.3 High 2026-07-21
CVE-2026-47685 FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page — fogproject CWE-79 7.3 High 2026-07-21
CVE-2026-33739 FOG has Stored XSS in Multiple Management Pages — fogproject CWE-79 5.7 Medium 2026-03-27
CVE-2026-24138 FOG vulnerable to unauthenticated SSRF via `/fog/service/getversion.php` — fogproject CWE-918 7.5 High 2026-01-23
CVE-2025-58443 FOG's authentication bypass leads to full SQL DB dump — fogproject CWE-306 9.8AI Critical AI 2025-09-06
CVE-2024-42349 FOG has a Log Information Disclosure — fogproject CWE-532 5.3 Medium 2024-08-02
CVE-2024-42348 FOG leaks sensitive information (AD domain, username and password) — fogproject CWE-77 9.3 Critical 2024-08-02
CVE-2024-41954 FOG Weak file permissions — fogproject CWE-732 5.3 Medium 2024-07-31
CVE-2024-41108 FOG Sensitive Information Disclosure — fogproject CWE-200 7.5 High 2024-07-31
CVE-2024-40645 FOG Authenticated File Upload RCE — fogproject CWE-434 8.8 High 2024-07-31
CVE-2024-39916 NFS server misconfiguration allows file access outside the exported directory — fogproject CWE-453 6.4 Medium 2024-07-12
CVE-2024-39914 FOG has a command injection in /fog/management/export.php?filename= — fogproject CWE-77 9.8 Critical 2024-07-12
CVE-2023-46237 FOG path traversal via unauthenticated endpoint — fogproject CWE-22 5.8 Medium 2023-10-31
CVE-2023-46236 FOG SSRF via unauthenticated endpoint(s) — fogproject CWE-918 8.6 High 2023-10-31
CVE-2023-46235 FOG stored XSS on log screen via unsanitized request logging — fogproject CWE-79 5.4 Medium 2023-10-31

This page lists every published CVE security advisory associated with FOGProject. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.