CVE-2020-23572: Beescms
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
Affected products
- Beescms Beescms: version 4.0 only
Published 2021-11-08. Last modified 2026-06-17.