High severity8.8NVD Advisory· Published Jul 7, 2021· Updated Jun 17, 2026
CVE-2021-28931
CVE-2021-28931
Description
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
forkcms/forkcmsPackagist | < 5.9.3 | 5.9.3 |
Affected products
3- Fork/CMSdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-748f-wv76-x9hgghsaADVISORY
- github.com/bousalman/ForkCMS-arbitrary-upload/blob/main/README.mdnvdThird Party AdvisoryWEB
- github.com/forkcms/forkcms/releases/tag/5.9.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-28931ghsaADVISORY
- github.com/forkcms/forkcms/pull/3351ghsaWEB
News mentions
0No linked articles in our index yet.