← Vulnerability feed

Vulnerability record · CVE-2018-20773 · published 11 February 2019

CVE-2018-20773: Frog cms project frog cms code injection vulnerability

FFrog Cms Project · Frog Cms

Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.

7.2 CVSS 3.0 High EPSS 2.1% · top 19.0% CWE-94 · Code injection
7.2CVSS 3.0 base score, v2 6.5
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/philippe/FrogCMS/issues/23 ExploitThird Party Advisory
https://github.com/philippe/FrogCMS/issues/23 ExploitThird Party Advisory

Track CVE-2018-20773 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-4912Frog cms project frog cms unrestricted file upload vulnerabilityAn Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.EPSS 8.1%8.8CVE-2018-8908Frog cms project frog cms cross-site request forgery vulnerabilityAn issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craf…EPSS 2.2%7.5CVE-2018-20776Frog cms project frog cms information exposure vulnerabilityFrog CMS 0.9.5 provides a directory listing for a /public request.EPSS 1.5%7.2CVE-2018-20775Frog cms project frog cms code injection vulnerabilityadmin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file …EPSS 2.1%7.2CVE-2018-20772Frog cms project frog cms code injection vulnerabilityFrog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.EPSS 2.1%7.2CVE-2018-11098Frog cms project frog cms unrestricted file upload vulnerabilityAn issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CV…EPSS 1.4%6.1CVE-2018-20778Frog cms project frog cms cross-site scripting vulnerabilityadmin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.EPSS 0.83%6.1CVE-2019-6243Frog cms project frog cms cross-site scripting vulnerabilityFrog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI).EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2018-20773), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.