CVE-2020-13485: Verbb Knock Knock
Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
Affected products
- Verbb Knock Knock: before 1.2.8 (fixed in 1.2.8)
Published 2020-05-25. Last modified 2026-06-17.