CVE-2020-28693: Horizontcms Project Horizontcms
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>
Affected products
- Horizontcms Project Horizontcms: version 1.0.0 only
Published 2020-11-16. Last modified 2026-06-17.