CVE-2020-37023: Koken CMS

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

Affected products

  • Koken Koken CMS: version 0.22.24 only

Published 2026-01-30. Last modified 2026-06-17.