Skip to main content

Vendor/product archive

fork-cms / fork_cms CVEs

Beta · best-effort

25 CVEs tagged to fork-cms / fork_cms1 Critical, 7 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2022-35590

Published Aug 12, 2022

A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameter

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35589

Published Aug 12, 2022

A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35587

Published Aug 12, 2022

A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parameter

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35585

Published Aug 12, 2022

A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parameter

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1064

Published Mar 25, 2022

SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0145

Published Mar 24, 2022

Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23049

Published Oct 22, 2021

Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28931

Published Jul 7, 2021

Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23264

Published May 6, 2021

Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23263

Published May 6, 2021

Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the "navigation_title" parameter and the "t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24036

Published Mar 4, 2021

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23960

Published Jan 11, 2021

Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9470

Published Feb 8, 2020

Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork CMS before 3.8.4 allows remote attackers to inject arbitrary…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20682

Published Jan 9, 2019

Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17595

Published Oct 2, 2018

In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1467

Published Feb 6, 2015

Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) ty…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5164

Published Sep 26, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the term parameter to (1) autocomple…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1188

Published Sep 26, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1209

Published Feb 24, 2012

Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1208

Published Feb 24, 2012

Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arb…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1207

Published Feb 24, 2012

Directory traversal vulnerability in frontend/core/engine/javascript.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to read arbitrary files…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1