CVE-2020-28693: Horizontcms Project Horizontcms

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>

Affected products

Published 2020-11-16. Last modified 2026-06-17.