MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler.
Conclusion & alert: CVE-2020-12471 is rated High Exploit Risk (85.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.25%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.26% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2020-12471
Exploit prediction scoring system (EPSS) score for CVE-2020-12471
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).