Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.
References
| Link | Resource |
|---|---|
| https://sourceforge.net/projects/navigatecms | Product |
| https://www.exploit-db.com/exploits/48548 | Exploit Third Party Advisory VDB Entry |
| https://www.navigatecms.com/en/home | Product |
| https://www.vulncheck.com/advisories/navigate-cms-cross-site-request-forgery | Broken Link |
Configurations
History
13 Feb 2026, 17:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://sourceforge.net/projects/navigatecms - Product | |
| References | () https://www.exploit-db.com/exploits/48548 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.navigatecms.com/en/home - Product | |
| References | () https://www.vulncheck.com/advisories/navigate-cms-cross-site-request-forgery - Broken Link | |
| First Time |
Naviwebs navigate Cms
Naviwebs |
|
| CPE | cpe:2.3:a:naviwebs:navigate_cms:2.8.7:*:*:*:*:*:*:* |
30 Jan 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-30 23:16
Updated : 2026-02-13 17:51
NVD link : CVE-2020-37054
Mitre link : CVE-2020-37054
CVE.ORG link : CVE-2020-37054
JSON object : View
Products Affected
naviwebs
- navigate_cms
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
