CVE-2020-8644
CVE-2020-8644 is a critical-severity vulnerability in Playsms with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2021-11-03). The underlying weakness is classified as CWE-94.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 87% (100th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2021-11-03)
- EU (EUVD) id: EUVD-2020-29492
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2021-11-03)
- Weakness: CWE-94
- Affected product: Playsms
- Published:
- Last modified:
Description
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
Frequently asked questions
- What is CVE-2020-8644?
- PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- How severe is CVE-2020-8644?
- CVE-2020-8644 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2020-8644 being actively exploited?
- Yes. CVE-2020-8644 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2021-11-03, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2020-8644?
- CVE-2020-8644 affects Playsms. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-8644?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2020-8644 have an EU (EUVD) identifier?
- Yes. CVE-2020-8644 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2020-29492. It is also flagged as exploited in the EUVD (since 2021-11-03).
- When was CVE-2020-8644 published?
- CVE-2020-8644 was published on 2020-02-05 and last updated on 2026-06-17.
References
- http://packetstormsecurity.com/files/157106/PlaySMS-index.php-Unauthenticated-Template-Injection-Code-Execution.html
- https://forum.playsms.org/t/playsms-1-4-3-has-been-released/2704
- https://playsms.org/2020/02/05/playsms-1-4-3-has-been-released/
- https://research.nccgroup.com/2020/02/11/technical-advisory-playsms-pre-authentication-remote-code-execution-cve-2020-8644/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8644
Affected products (1)
- cpe:2.3:a:playsms:playsms:*:*:*:*:*:*:*:*
More vulnerabilities in Playsms
- CVE-2022-47034 — Critical (CVSS 9.8): A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass…
- CVE-2021-40373 — Critical (CVSS 9.8): playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of…
- CVE-2017-9101 — Critical (CVSS 9.8): import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the…
- CVE-2017-9080 — High (CVSS 8.8): PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.…
- CVE-2009-0103 — High (CVSS 7.5): Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP…
- CVE-2008-5881 — High (CVSS 7.5): Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary…
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…