elitecms records
18 published records for vendor elitecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2022-30808No exploit | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.elitecms · elite cms · CWE-434 | Critical9.8 | — | 17.5% | Jun 2, 2022 |
41Plan | CVE-2022-24218No exploit | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.elitecms · elite cms | Critical9.1 | — | 17.0% | Feb 1, 2022 |
39Monitor | CVE-2021-46093No exploit | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.elitecms · elite cms · CWE-276 | Critical9.8 | — | 1.2% | Feb 1, 2022 |
39Monitor | CVE-2022-30814No exploit | elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Jun 2, 2022 |
39Monitor | CVE-2022-30816No exploit | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Jun 2, 2022 |
39Monitor | CVE-2022-30815No exploit | elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Jun 2, 2022 |
39Monitor | CVE-2022-30809No exploit | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Jun 2, 2022 |
39Monitor | CVE-2022-30810No exploit | elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Jun 2, 2022 |
39Monitor | CVE-2022-30813No exploit | elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Jun 2, 2022 |
39Monitor | CVE-2022-24220No exploit | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Feb 1, 2022 |
39Monitor | CVE-2022-24221No exploit | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Feb 1, 2022 |
39Monitor | CVE-2022-24222No exploit | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Feb 1, 2022 |
39Monitor | CVE-2022-24219No exploit | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.elitecms · elite cms · CWE-89 | Critical9.8 | — | 1.1% | Feb 1, 2022 |
35Monitor | CVE-2023-42331No exploit | A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.elitecms · elite cms · CWE-434 | High8.8 | — | 1.5% | Sep 20, 2023 |
30Monitor | CVE-2008-4046Proof of concept | SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.elitecms · elitecms · CWE-89 | High7.5 | — | 1.0% | Sep 11, 2008 |
28Monitor | CVE-2018-12250No exploit | An issue was discovered in Elite CMS Pro 2.01.elitecms · elite cms · CWE-89 | High7.2 | — | 1.6% | Jul 3, 2019 |
26Monitor | CVE-2022-30804No exploit | elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.elitecms · elite cms · CWE-22 | Medium6.5 | — | 1.1% | Jun 2, 2022 |
24Monitor | CVE-2022-40361No exploit | Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/logelitecms · elite cms · CWE-79 | Medium6.1 | — | 0.4% | Jan 10, 2024 |
- CVE-2022-3080844Plan
elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.
CriticalCVSS 9.8No exploitEPSS 17%elitecms · elite cmsJun 2, 2022
- CVE-2022-2421841Plan
An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.
CriticalCVSS 9.1No exploitEPSS 17%elitecms · elite cmsFeb 1, 2022
- CVE-2021-4609339Monitor
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsFeb 1, 2022
- CVE-2022-3081439Monitor
elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-3081639Monitor
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-3081539Monitor
elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-3080939Monitor
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-3081039Monitor
elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-3081339Monitor
elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-2422039Monitor
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsFeb 1, 2022
- CVE-2022-2422139Monitor
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsFeb 1, 2022
- CVE-2022-2422239Monitor
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsFeb 1, 2022
- CVE-2022-2421939Monitor
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
CriticalCVSS 9.8No exploitEPSS 1%elitecms · elite cmsFeb 1, 2022
- CVE-2023-4233135Monitor
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
HighCVSS 8.8No exploitEPSS 1%elitecms · elite cmsSep 20, 2023
- CVE-2008-404630Monitor
SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
HighCVSS 7.5Proof of conceptEPSS 1%elitecms · elitecmsSep 11, 2008
- CVE-2018-1225028Monitor
An issue was discovered in Elite CMS Pro 2.01.
HighCVSS 7.2No exploitEPSS 2%elitecms · elite cmsJul 3, 2019
- CVE-2022-3080426Monitor
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
MediumCVSS 6.5No exploitEPSS 1%elitecms · elite cmsJun 2, 2022
- CVE-2022-4036124Monitor
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/log
MediumCVSS 6.1No exploitEPSS 0%elitecms · elite cmsJan 10, 2024