CVE-2018-20775: Frog CMS Project Frog CMS
High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
Affected products
- Frog CMS Project Frog CMS: version 0.9.5 only
Published 2019-02-11. Last modified 2026-06-17.