CVE-2020-36388: Civicrm

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.

Affected products

  • Civicrm Civicrm: before 5.21.3 (fixed in 5.21.3); from 5.22.0, before 5.24.3 (fixed in 5.24.3)

Published 2021-06-17. Last modified 2026-06-17.