CVE-2020-20092: Articlecms Project Articlecms

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.

Affected products

Published 2021-05-13. Last modified 2026-06-17.