Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5776

40
FAUCET Score

CVE-2020-5776 describes a critical Cross-Site Request Forgery (CSRF) vulnerability in all versions of MAGMI, a Magento plugin. This flaw allows an attacker to leverage an existing administrator session to achieve Remote Code Execution (RCE) via the phpcli command, posing a severe risk to affected systems. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 99/100, the vulnerability is easily exploitable with low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, exploit intelligence indicates the existence of Nuclei templates for detection, and it has garnered significant community discussion and media coverage, including an article from BleepingComputer.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:magmi_project:magmi:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
14.72%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Nuclei: CVE-2020-5776 · Sep 4, 2020
This CVE's current EPSS score of 0.1472 is in the 96th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Patches (7)

esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
mariadbvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openrefinevendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted

Vendor Advisories (8)

composerGHSA-cv7m-wc7g-7gfpmedium

Cross-Site Request Forgery in MAGMI

May 6, 2021
twiliollm-twilio-c523158f6823ea6eMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
esetllm-eset-2cca93142aaba91aMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
hyperledgerllm-hyperledger-7abed9465eeee0f9MEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
pnpmllm-pnpm-648706aff9b8cfeeMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
omronllm-omron-c17b909bb3f34c5dMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
openrefinellm-openrefine-261598723f4c2e00MEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
mariadbllm-mariadb-d1ea3e268315b8e0MEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020

References

tenable.com / security/research/tra-2020-51
Third Party Advisory