ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-35587
+3 in the same advisory: …35585 …35589 …35590
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parameter

A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parameter

NVD description · AI analysis pending
4.8<1% PoC
  • fork-cms fork cms
CVE-2022-1064
SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

NVD description · AI analysis pending
8.81% PoC
  • fork-cms fork cms
CVE-2022-0153
+1 in the same advisory: …0145
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

NVD description · AI analysis pending
7.5
group max
1% PoC
  • fork-cms fork cms
CVE-2020-23049
Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`,

Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web scripts or HTML.

NVD description · AI analysis pending
5.4<1% PoC
  • fork-cms fork cms
CVE-2021-28931
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uplo

Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.

NVD description · AI analysis pending
8.81%
  • fork-cms fork cms
CVE-2020-23264
+1 in the same advisory: …23263
Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.

Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.

NVD description · AI analysis pending
8.8
group max
<1%
  • fork-cms fork cms
CVE-2020-24036
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

NVD description · AI analysis pending
8.83% PoC ×3
  • fork-cms fork cms
CVE-2020-23960
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as

Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) approve the mass of the user's comments, (2) restoring a deleted user, (3) installing or running modules, (4) resetting the analytics, (5) pinging the mailmotor api, (6) uploading things to the media library, (7) exporting locale.

NVD description · AI analysis pending
8.8<1%
  • fork-cms fork cms
CVE-2020-13633
Fork before 5.8.3 allows XSS via navigation_title or title.

Fork before 5.8.3 allows XSS via navigation_title or title.

NVD description · AI analysis pending
6.1<1%
  • fork-cms fork cms
CVE-2019-15521
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.

Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.

NVD description · AI analysis pending
9.82%
  • spoon-library spoon library
  • spoon-library fork cms
CVE-2018-20682
Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).

Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).

NVD description · AI analysis pending
5.4<1% PoC
  • fork-cms fork cms
CVE-2018-17595
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.

In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.

NVD description · AI analysis pending
6.11%
  • fork-cms fork cms
CVE-2018-5215
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.

Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • fork-cms fork cms