CVE-2020-13633
PHP vulnerability analysis and mitigation

Overview

Fork CMS before version 5.8.3 contained a Cross-Site Scripting (XSS) vulnerability that allowed attackers to inject malicious JavaScript code via the navigation_title or title parameters. The vulnerability was discovered and disclosed on May 27, 2020 (CISA Bulletin, MITRE).

Technical details

The vulnerability existed due to insufficient input validation of the navigation_title and title fields in the content management system. This allowed HTML with embedded JavaScript to be injected and executed in both the frontend and backend interfaces. The vulnerability was assigned a CVSS score of 4.3, indicating medium severity (CISA Bulletin).

Impact

Successful exploitation of this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of other users' browsers, potentially leading to theft of sensitive information, session hijacking, or other malicious actions (GitHub PR).

Exploitability

The vulnerability could be exploited by an attacker who has access to create or modify content in the CMS, specifically through the navigation_title or title fields (GitHub PR).

Mitigation and workarounds

The vulnerability was fixed in Fork CMS version 5.8.3 by implementing proper input validation that allows HTML but strips out JavaScript content. Users should upgrade to version 5.8.3 or later to protect against this vulnerability (GitHub PR).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management