CVE-2020-24036: Fork-CMS Fork CMS
High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
Affected products
- Fork-CMS Fork CMS: before 5.8.3 (fixed in 5.8.3)
Published 2021-03-04. Last modified 2026-07-09.