Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-47687 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders ` ` labels using raw, unescaped user input. An unauthenticated attacker who knows any registered host's MAC address can POST a malicious `sysproduct` value to `/service/inventory.php`, which is stored in the database. When an administrator opens Reports > Inventory, the payload breaks out of the ` ` element and executes arbitrary JavaScript in the admin's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue. NVD description · AI analysis pending | 8.7 group max | <1% | PoC |
| — | |
| CVE-2026-33739 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter sanitization in record creations/updates and a lack of HTML escaping in listing tables. Version 1.5.10.1812 patches the issue. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2025-58443 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be released 9/15/2025. To address this vulnerability immediately, upgrade to the latest version of either the dev-branch or working-1.6 branch. This will patch the issue for users concerned about immediate exposure. See the FOG Project documentation for step-by-step upgrade instructions: https://docs.fogproject.org/en/latest/install-fog-server#choosing-a-fog-version. NVD description · AI analysis pending | 9.9 | 19% | PoC |
| — | |
| CVE-2024-42348 +1 in the same advisory: …42349 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395. NVD description · AI analysis pending | 8.6 group max | <1% | PoC |
| — | |
| CVE-2024-40645 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebranding feature has a check on the client banner image requiring it to be 650 pixels wide and 120 pixels high. Apart from that, there are no checks on things like file extensions. This can be abused by appending a PHP webshell to the end of the image and changing the extension to anything the PHP web server will parse. This vulnerability is fixed in 1.5.10.41. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2024-39914 +1 in the same advisory: …39916 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34. NVD description · AI analysis pending | 9.8 group max | 23% | PoC |
| — | |
| CVE-2024-34477 | configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash a configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In order to exploit the vulnerability, someone needs to mount an NFS share in order to add an executable file as root. In addition, the SUID bit must be added to this file. NVD description · AI analysis pending | 7.8 | <1% | PoC ×2 |
| — | |
| CVE-2023-46236 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme. This also allows remote access to files visible to the Apache user group. Other impacts vary based on server configuration. Version 1.5.10 contains a patch. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2021-32243 | FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated). FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated). NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — |