Known Vulnerabilities for products from Fork-cms

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Fork-cms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-32710 Not Provided 2026-03-20 2026-03-27
CVE-2022-0153 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-24 2022-03-29
CVE-2022-0145 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.4 - MEDIUM 2022-03-24 2022-03-29
CVE-2021-28931 Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes di... 8.8 - HIGH 2021-07-07 2021-07-12
CVE-2020-24036 PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user t... 8.8 - HIGH 2021-03-04 2021-07-21
CVE-2020-23960 Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers ... 8.8 - HIGH 2021-01-11 2021-07-12
CVE-2020-23264 Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged admi... 8.8 - HIGH 2021-05-06 2021-05-12
CVE-2020-23263 Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascrip... 6.1 - MEDIUM 2021-05-06 2021-05-12
CVE-2020-23049 Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displa... 5.4 - MEDIUM 2021-10-22 2021-10-28
CVE-2020-13633 Fork before 5.8.3 allows XSS via navigation_title or title. 6.1 - MEDIUM 2020-05-27 2020-05-27
CVE-2019-15521 Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cook... 9.8 - CRITICAL 2019-08-26 2019-08-28
CVE-2018-20682 Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Faceb... 5.4 - MEDIUM 2019-01-09 2019-01-23
CVE-2018-17595 In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend... 6.1 - MEDIUM 2018-10-02 2018-11-16
CVE-2018-5215 Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter. 5.4 - MEDIUM 2018-01-04 2018-01-16
CVE-2015-1467 Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute a... 7.5 - HIGH 2015-02-06 2018-10-09
CVE-2014-9470 Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork CMS be... 6.1 - MEDIUM 2020-02-08 2020-02-12
CVE-2012-5164 Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web s... 4.3 - MEDIUM 2012-09-26 2017-08-29
CVE-2012-1209 Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before... 4.3 - MEDIUM 2012-02-24 2018-01-11
CVE-2012-1208 Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other vers... 4.3 - MEDIUM 2012-02-24 2012-02-24
CVE-2012-1207 Directory traversal vulnerability in frontend/core/engine/javascript.php in Fork CMS 3.2.4 and possibly other versions before... 5 - MEDIUM 2012-02-24 2017-08-29

Known software with vulnerabilities from Fork-cms

Type Vendor Product Version
ApplicationFork-cmsFork2.0.0
ApplicationFork-cmsFork Cms1.3.1
ApplicationFork-cmsForkcms2.0.0