VulnSea

fogproject has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 7.3 (high). The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
Last 90 days
4 prev 0

Weakness classes

Products

  • fogproject 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

fogproject vulnerabilities

CVEs affecting fogproject, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-47689Medium· 4.6
2mo ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates …

Sunlitfogproject · fogprojectEPSS 0.32%via NVD
CVE-2026-47688High· 8.2
2mo ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker v…

Twilightfogproject · fogprojectEPSS 0.18%via NVD
CVE-2026-47687High· 7.3
2mo ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user i…

Twilightfogproject · fogprojectEPSS 0.27%via NVD
CVE-2026-47685High· 7.3
2mo ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied val…

Twilightfogproject · fogprojectEPSS 0.25%via NVD
fogproject vulnerabilities (CVEs) · VulnSea