CVE-2020-36999: Elaniin CMS

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL injection. Attackers can bypass authentication by sending crafted email and password parameters with '=''or' payload to login.php, granting unauthorized access to the system.

Affected products

  • Elaniin Elaniin CMS: version 1.0 only

Published 2026-01-29. Last modified 2026-06-17.