S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Misconfiguration·Updated Jan 12, 2026

Fork CMS Installation Page Exposure Scanner

This scanner checks for accessible /install/ endpoints in Fork CMS deployments, enabling attackers to reinstall or overwrite the CMS configuration.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Fork CMS is an open-source content management system designed for simplicity and flexibility, used by developers and businesses to build and manage websites. It offers a user-friendly interface for content editing, modular extensions, and a clean codebase, making it popular for small to medium-sized projects. The platform relies on a one-time installation process to set up database connections and admin credentials.

The vulnerability arises when the installation page remains accessible after the initial setup. Fork CMS does not automatically remove or lock the installer directory, leaving it exposed to anyone who knows the URL. This oversight allows an attacker to re-run the installation wizard, potentially overwriting existing configurations or creating a new admin account.

Specifically, the scanner targets the /install/ directory and related files like install.php or index.php within that path. These endpoints are intended for initial setup only and should be deleted or restricted post-installation. The scanner verifies if these pages return HTTP 200 responses, indicating they are still live and exploitable.

If exploited, an attacker can gain full administrative access to the Fork CMS instance, modify website content, inject malicious code, or exfiltrate sensitive data. The CVSS score of 9.0 reflects the critical impact due to the potential for complete compromise of the CMS and its underlying server.

Solution Advice
  • Delete the /install/ directory and all its contents from the web server after completing the Fork CMS setup.
  • Implement web server rules (e.g., .htaccess or Nginx config) to deny access to the /install/ path from any IP address.
  • Use file permissions to make the installer directory read-only or remove execute permissions for the web server user.
  • Regularly audit the web root for leftover installation files using automated scanners or manual checks.
  • Apply a web application firewall (WAF) rule to block requests containing /install/ in the URL.
  • Monitor server access logs for repeated attempts to access /install/ endpoints and trigger alerts.
  • Ensure the Fork CMS installation is updated to the latest version, which may include automatic cleanup of installer files.
  • Restrict administrative access to the CMS to trusted IP ranges and enforce strong authentication for all admin accounts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.