Fork Cms is a modestly represented open-source content management system with a focused product footprint centered on a single core platform. Despite its narrow portfolio, the vendor has generated a notable volume of disclosures over time, reflecting the complexity inherent to a web-facing CMS that handles user input, authentication, and content management across a broad codebase. The disclosed vulnerabilities span multiple weakness classes without a single dominant pattern, suggesting exposure across different architectural layers rather than a concentrated class-specific risk. Defenders deploying this platform should apply available patches systematically and monitor upstream releases; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fork Cms over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24036HIGH PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code. | Mar 4, 2021 | 8.8 | 30 | NO | NO |
CVE-2019-15521CRITICAL Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object. | Aug 26, 2019 | 9.8 | 29 | NO | NO |
CVE-2015-1467HIGH Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) typ | Feb 6, 2015 | 7.5 | 28 | NO | YES |
CVE-2020-23264HIGH Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators. | May 6, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-23960HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) | Jan 11, 2021 | 8.8 | 26 | NO | NO |
CVE-2012-1188MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring param | Sep 26, 2012 | 4.3 | 26 | NO | YES |
CVE-2012-1208MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbi | Feb 24, 2012 | 4.3 | 26 | NO | YES |
CVE-2021-28931HIGH Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes p | Jul 7, 2021 | 8.8 | 25 | NO | NO |
CVE-2022-0153HIGH SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1. | Mar 24, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-1064HIGH SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1. | Mar 25, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fork Cms.
Media articles that mention a CVE ID that affects a product developed by Fork Cms — matched by CVE ID, not by vendor name.