Skip to content
Noroxi

ritecms records

17 published records for vendor ritecms.

All records

17 records
  • An issue was discovered in RiteCMS 2.2.1.

    HighCVSS 8.8Proof of conceptEPSS 16%

    ritecms · ritecmsAug 18, 2020

  • RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.

    HighCVSS 7.2No exploitEPSS 30%

    ritecms · ritecmsApr 8, 2022

  • RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.

    MediumCVSS 6.5No exploitEPSS 21%

    ritecms · ritecmsApr 12, 2022

  • A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal

    HighCVSS 7.5No exploitEPSS 1%

    ritecms · ritecmsDec 17, 2025

  • Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

    HighCVSS 7.5No exploitEPSS 1%

    ritecms · ritecmsDec 17, 2025

  • CVE-2013-5316
    28Monitor

    Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for

    MediumCVSS 6.8Proof of conceptEPSS 2%

    ritecms · ritecmsAug 20, 2013

  • RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

    HighCVSS 7.2No exploitEPSS 1%

    ritecms · ritecmsDec 17, 2025

  • RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.

    MediumCVSS 6.5No exploitEPSS 4%

    ritecms · ritecmsApr 12, 2022

  • A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via

    MediumCVSS 6.8No exploitEPSS 0%

    ritecms · ritecmsDec 17, 2025

  • RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    ritecms · ritecmsMar 13, 2024

  • A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's

    MediumCVSS 6.1No exploitEPSS 0%

    ritecms · ritecmsDec 17, 2025

  • Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload in

    MediumCVSS 5.4Proof of conceptEPSS 1%

    ritecms · ritecmsSep 28, 2023

  • RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

    MediumCVSS 5.3No exploitEPSS 0%

    ritecms · ritecmsDec 17, 2025

  • Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the G

    MediumCVSS 4.8Proof of conceptEPSS 1%

    ritecms · ritecmsSep 28, 2023

  • Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in

    MediumCVSS 4.8Proof of conceptEPSS 1%

    ritecms · ritecmsOct 4, 2023

  • A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

    MediumCVSS 4.8Proof of conceptEPSS 0%

    ritecms · ritecmsOct 25, 2023

  • CVE-2013-5317
    15Monitor

    Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the m

    LowCVSS 3.5Proof of conceptEPSS 3%

    ritecms · ritecmsAug 20, 2013