Horizontcms Project maintains a content management system whose vulnerability profile centers on file-handling and access-control issues, particularly unrestricted file uploads and improper exposure of sensitive directories and files. This represents a narrow but structurally important attack surface characteristic of web-based CMS platforms where upload and permissions logic is a frequent source of compromise; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Horizontcms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27387HIGH An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP cod | Nov 5, 2020 | 8.8 | 48 | NO | YES |
CVE-2021-28428CRITICAL File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulner | Apr 5, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-28693HIGH An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PH | Nov 16, 2020 | 8.8 | 26 | NO | NO |
CVE-2022-25104HIGH HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/. | Feb 24, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Horizontcms Project.
Media articles that mention a CVE ID that affects a product developed by Horizontcms Project — matched by CVE ID, not by vendor name.