fogproject vulnerabilities
CVEs whose affected-version data names the fogproject package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-47689Medium· 4.6FOG is a free open-source cloning/imaging/rescue suite/inventory management system
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates …
CVE-2026-47688High· 8.2FOG is a free open-source cloning/imaging/rescue suite/inventory management system
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker v…
CVE-2026-47687High· 7.3FOG is a free open-source cloning/imaging/rescue suite/inventory management system
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user i…
CVE-2026-47685High· 7.3FOG is a free open-source cloning/imaging/rescue suite/inventory management system
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied val…