Medium severity6.1NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026
CVE-2020-23263
CVE-2020-23263
Description
Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the "navigation_title" parameter and the "title" parameter in /private/en/pages/add.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
forkcms/forkcmsPackagist | < 5.8.3 | 5.8.3 |
Affected products
3- Fork CMS/Fork CMSdescription
Patches
Vulnerability mechanics
References
3- github.com/forkcms/forkcms/pull/3093nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vp4x-94ff-2cmvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-23263ghsaADVISORY
News mentions
0No linked articles in our index yet.