CVE-2020-37186Disclosure

LOWCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Mentions · 2026-02-18: 1Active Exploitation · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-18: 102-1102-1202-18
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-121
Active Exploitation1
2026-02-181
Disclosure1
Full discourse3 posts
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical code injection in #Chevereto core. CVE-2020-37186 CVSS: 9.8. A remote attacker without any user interaction can cause #RCE. It's actively exploited #CISA #KEV #Patch #Patch #Patch

    Post summary

    Chevereto’s core is vulnerable to CVE-2020-37186, a critical remote code execution flaw with a CVSS score of 9.8, and it is actively exploited in the wild; users should apply the available patch immediately.

    00001281
    7.2K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2020-37186: CRITICAL] Beware of the remote code execution vulnerability in Chevereto 3.13.4 Core! Attackers can inject malicious code during DB configuration installation by manipulating the table prefi...#cve,CVE-2020-37186,#cybersecurity https://cvefind.com/CVE-2020-37186

    Post summary

    The post alerts readers to a critical remote code execution vulnerability (CVE‑2020‑37186) in Chevereto 3.13.4 Core that lets attackers inject malicious code via database configuration. No exploit code, patch details, or evidence of active exploitation is provided.

    0000053
    578 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2020-37186 Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attack… https://www.cve.org/CVERecord?id=CVE-2020-37186

    Post summary

    The text reports a remote code execution vulnerability in Chevereto 3.13.4, allowing code injection during database setup, without providing PoC, exploitation evidence, or patch details.

    00000165
    56.5K followersView on X

Explore more