OpenRapid records
16 published records for vendor openrapid.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-4446No exploit | OpenRapid RapidCMS category.php sql injectionopenrapid · rapidcms · CWE-89 | Critical9.8 | — | 0.7% | Aug 20, 2023 |
39Monitor | CVE-2023-4448No exploit | OpenRapid RapidCMS run-movepass.php password recoveryopenrapid · rapidcms · CWE-640 | Critical9.8 | — | 0.7% | Aug 20, 2023 |
39Monitor | CVE-2023-4447No exploit | OpenRapid RapidCMS article-chat.php sql injectionopenrapid · rapidcms · CWE-89 | Critical9.8 | — | 0.6% | Aug 20, 2023 |
39Monitor | CVE-2023-5258No exploit | OpenRapid RapidCMS addgood.php sql injectionopenrapid · rapidcms · CWE-89 | Critical9.8 | — | 0.6% | Sep 29, 2023 |
39Monitor | CVE-2024-44838No exploit | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.openrapid · rapidcms · CWE-89 | Critical9.8 | — | 0.5% | Sep 6, 2024 |
39Monitor | CVE-2024-45771No exploit | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.openrapid · rapidcms · CWE-89 | Critical9.8 | — | 0.5% | Sep 6, 2024 |
39Monitor | CVE-2024-44839No exploit | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.openrapid · rapidcms · CWE-89 | Critical9.8 | — | 0.5% | Sep 6, 2024 |
36Monitor | CVE-2023-3852No exploit | OpenRapid RapidCMS upload.php unrestricted uploadopenrapid · rapidcms · CWE-434 | High7.2 | — | 25.2% | Jul 23, 2023 |
35Monitor | CVE-2023-5262No exploit | OpenRapid RapidCMS uploadicon.php isImg unrestricted uploadopenrapid · rapidcms · CWE-434 | High8.8 | — | 0.6% | Sep 29, 2023 |
28Monitor | CVE-2023-5033No exploit | OpenRapid RapidCMS cate-edit-run.php sql injectionopenrapid · rapidcms · CWE-89 | High7.2 | — | 0.7% | Sep 18, 2023 |
28Monitor | CVE-2023-5032No exploit | OpenRapid RapidCMS article-edit-run.php sql injectionopenrapid · rapidcms · CWE-89 | High7.2 | — | 0.6% | Sep 18, 2023 |
26Monitor | CVE-2023-5031No exploit | OpenRapid RapidCMS article-add.php sql injectionopenrapid · rapidcms · CWE-89 | Medium6.5 | — | 0.5% | Sep 17, 2023 |
24Monitor | CVE-2025-64047No exploit | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.openrapid · rapidcms · CWE-79 | Medium6.1 | — | 0.2% | Nov 24, 2025 |
24Monitor | CVE-2025-64046No exploit | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.openrapid · rapidcms · CWE-79 | Medium6.1 | — | 0.2% | Nov 17, 2025 |
21Monitor | CVE-2024-8335No exploit | OpenRapid RapidCMS runlogon.php sql injectionopenrapid · rapidcms · CWE-89 | Medium5.3 | — | 0.6% | Aug 30, 2024 |
21Monitor | CVE-2024-8331No exploit | OpenRapid RapidCMS user-move-run.php sql injectionopenrapid · rapidcms · CWE-89 | Medium5.3 | — | 0.6% | Aug 30, 2024 |
- CVE-2023-444639Monitor
OpenRapid RapidCMS category.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%openrapid · rapidcmsAug 20, 2023
- CVE-2023-444839Monitor
OpenRapid RapidCMS run-movepass.php password recovery
CriticalCVSS 9.8No exploitEPSS 1%openrapid · rapidcmsAug 20, 2023
- CVE-2023-444739Monitor
OpenRapid RapidCMS article-chat.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%openrapid · rapidcmsAug 20, 2023
- CVE-2023-525839Monitor
OpenRapid RapidCMS addgood.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%openrapid · rapidcmsSep 29, 2023
- CVE-2024-4483839Monitor
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.
CriticalCVSS 9.8No exploitEPSS 1%openrapid · rapidcmsSep 6, 2024
- CVE-2024-4577139Monitor
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.
CriticalCVSS 9.8No exploitEPSS 0%openrapid · rapidcmsSep 6, 2024
- CVE-2024-4483939Monitor
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.
CriticalCVSS 9.8No exploitEPSS 0%openrapid · rapidcmsSep 6, 2024
- CVE-2023-385236Monitor
OpenRapid RapidCMS upload.php unrestricted upload
HighCVSS 7.2No exploitEPSS 25%openrapid · rapidcmsJul 23, 2023
- CVE-2023-526235Monitor
OpenRapid RapidCMS uploadicon.php isImg unrestricted upload
HighCVSS 8.8No exploitEPSS 1%openrapid · rapidcmsSep 29, 2023
- CVE-2023-503328Monitor
OpenRapid RapidCMS cate-edit-run.php sql injection
HighCVSS 7.2No exploitEPSS 1%openrapid · rapidcmsSep 18, 2023
- CVE-2023-503228Monitor
OpenRapid RapidCMS article-edit-run.php sql injection
HighCVSS 7.2No exploitEPSS 1%openrapid · rapidcmsSep 18, 2023
- CVE-2023-503126Monitor
OpenRapid RapidCMS article-add.php sql injection
MediumCVSS 6.5No exploitEPSS 1%openrapid · rapidcmsSep 17, 2023
- CVE-2025-6404724Monitor
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
MediumCVSS 6.1No exploitEPSS 0%openrapid · rapidcmsNov 24, 2025
- CVE-2025-6404624Monitor
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
MediumCVSS 6.1No exploitEPSS 0%openrapid · rapidcmsNov 17, 2025
- CVE-2024-833521Monitor
OpenRapid RapidCMS runlogon.php sql injection
MediumCVSS 5.3No exploitEPSS 1%openrapid · rapidcmsAug 30, 2024
- CVE-2024-833121Monitor
OpenRapid RapidCMS user-move-run.php sql injection
MediumCVSS 5.3No exploitEPSS 1%openrapid · rapidcmsAug 30, 2024