Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fork Cms

First CVE: Feb 24, 2012Active for: 14 yearsTotal CVEs: 50

Fork Cms is a modestly represented open-source content management system with a focused product footprint centered on a single core platform. Despite its narrow portfolio, the vendor has generated a notable volume of disclosures over time, reflecting the complexity inherent to a web-facing CMS that handles user input, authentication, and content management across a broad codebase. The disclosed vulnerabilities span multiple weakness classes without a single dominant pattern, suggesting exposure across different architectural layers rather than a concentrated class-specific risk. Defenders deploying this platform should apply available patches systematically and monitor upstream releases; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
3.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fork Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2012
14 years ago
Most Recent CVE
Aug 12, 2022
1,442 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-24036HIGH
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
Mar 4, 20218.830NONO
CVE-2019-15521CRITICAL
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
Aug 26, 20199.829NONO
CVE-2015-1467HIGH
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) typ
Feb 6, 20157.528NOYES
CVE-2020-23264HIGH
Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.
May 6, 20218.827NONO
CVE-2020-23960HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1)
Jan 11, 20218.826NONO
CVE-2012-1188MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring param
Sep 26, 20124.326NOYES
CVE-2012-1208MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbi
Feb 24, 20124.326NOYES
CVE-2021-28931HIGH
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes p
Jul 7, 20218.825NONO
CVE-2022-0153HIGH
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.
Mar 24, 20227.524NONO
CVE-2022-1064HIGH
SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.
Mar 25, 20228.822NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
68%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (76.0%)
Unknown6 (24.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (76.0%)
High0 (0.0%)
Unknown6 (24.0%)
User Interaction
None5 (20.0%)
Unknown6 (24.0%)
Required14 (56.0%)
Privileges Required
Low7 (28.0%)
High4 (16.0%)
None8 (32.0%)
Unknown6 (24.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
12.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fork Cms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fork Cms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fork Cms's Products

View all 2 CNAs →

Top CWEs