AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-14209

HIGH · CVSS 8.8 EPSS 27.48% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-09-02 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 27.5% probability of exploitation in the next 30 days.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2020-14209
Severity
HIGH
CVSS
8.8
EPSS
27.48%

Original NVD Description

Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).

Related CVEs

Other vulnerabilities affecting the same vendor(s)