ritecms records
17 published records for vendor ritecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-23934Proof of concept | An issue was discovered in RiteCMS 2.2.1.ritecms · ritecms · CWE-78 | High8.8 | — | 16.0% | Aug 18, 2020 |
37Monitor | CVE-2021-46367No exploit | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.ritecms · ritecms · CWE-434 | High7.2 | — | 29.7% | Apr 8, 2022 |
32Monitor | CVE-2022-24248No exploit | RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.ritecms · ritecms · CWE-22 | Medium6.5 | — | 21.0% | Apr 12, 2022 |
30Monitor | CVE-2025-67174No exploit | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal ritecms · ritecms · CWE-22 | High7.5 | — | 1.3% | Dec 17, 2025 |
30Monitor | CVE-2025-67171No exploit | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.ritecms · ritecms · CWE-22 | High7.5 | — | 0.8% | Dec 17, 2025 |
28Monitor | CVE-2013-5316Proof of concept | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for ritecms · ritecms · CWE-352 | Medium6.8 | — | 2.3% | Aug 20, 2013 |
28Monitor | CVE-2025-67172No exploit | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.ritecms · ritecms · CWE-78 | High7.2 | — | 0.9% | Dec 17, 2025 |
27Monitor | CVE-2022-24247No exploit | RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.ritecms · ritecms · CWE-22 | Medium6.5 | — | 4.2% | Apr 12, 2022 |
27Monitor | CVE-2025-67173No exploit | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages viaritecms · ritecms · CWE-352 | Medium6.8 | — | 0.2% | Dec 17, 2025 |
24Monitor | CVE-2024-28623Proof of concept | RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.ritecms · ritecms · CWE-79 | Medium6.1 | — | 1.3% | Mar 13, 2024 |
24Monitor | CVE-2025-67170No exploit | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user'sritecms · ritecms · CWE-20 | Medium6.1 | — | 0.3% | Dec 17, 2025 |
21Monitor | CVE-2023-43878Proof of concept | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload inritecms · ritecms · CWE-79 | Medium5.4 | — | 0.5% | Sep 28, 2023 |
21Monitor | CVE-2025-67168No exploit | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.ritecms · ritecms · CWE-916 | Medium5.3 | — | 0.1% | Dec 17, 2025 |
19Monitor | CVE-2023-43879Proof of concept | Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Gritecms · ritecms · CWE-79 | Medium4.8 | — | 0.5% | Sep 28, 2023 |
19Monitor | CVE-2023-43877Proof of concept | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted inritecms · ritecms · CWE-79 | Medium4.8 | — | 0.5% | Oct 4, 2023 |
19Monitor | CVE-2023-44767Proof of concept | A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.ritecms · ritecms · CWE-79 | Medium4.8 | — | 0.5% | Oct 25, 2023 |
15Monitor | CVE-2013-5317Proof of concept | Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mritecms · ritecms · CWE-79 | Low3.5 | — | 2.6% | Aug 20, 2013 |
- CVE-2020-2393440Plan
An issue was discovered in RiteCMS 2.2.1.
HighCVSS 8.8Proof of conceptEPSS 16%ritecms · ritecmsAug 18, 2020
- CVE-2021-4636737Monitor
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.
HighCVSS 7.2No exploitEPSS 30%ritecms · ritecmsApr 8, 2022
- CVE-2022-2424832Monitor
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.
MediumCVSS 6.5No exploitEPSS 21%ritecms · ritecmsApr 12, 2022
- CVE-2025-6717430Monitor
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal
HighCVSS 7.5No exploitEPSS 1%ritecms · ritecmsDec 17, 2025
- CVE-2025-6717130Monitor
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.
HighCVSS 7.5No exploitEPSS 1%ritecms · ritecmsDec 17, 2025
- CVE-2013-531628Monitor
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for
MediumCVSS 6.8Proof of conceptEPSS 2%ritecms · ritecmsAug 20, 2013
- CVE-2025-6717228Monitor
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
HighCVSS 7.2No exploitEPSS 1%ritecms · ritecmsDec 17, 2025
- CVE-2022-2424727Monitor
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.
MediumCVSS 6.5No exploitEPSS 4%ritecms · ritecmsApr 12, 2022
- CVE-2025-6717327Monitor
A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via
MediumCVSS 6.8No exploitEPSS 0%ritecms · ritecmsDec 17, 2025
- CVE-2024-2862324Monitor
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
MediumCVSS 6.1Proof of conceptEPSS 1%ritecms · ritecmsMar 13, 2024
- CVE-2025-6717024Monitor
A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's
MediumCVSS 6.1No exploitEPSS 0%ritecms · ritecmsDec 17, 2025
- CVE-2023-4387821Monitor
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload in
MediumCVSS 5.4Proof of conceptEPSS 1%ritecms · ritecmsSep 28, 2023
- CVE-2025-6716821Monitor
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
MediumCVSS 5.3No exploitEPSS 0%ritecms · ritecmsDec 17, 2025
- CVE-2023-4387919Monitor
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the G
MediumCVSS 4.8Proof of conceptEPSS 1%ritecms · ritecmsSep 28, 2023
- CVE-2023-4387719Monitor
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in
MediumCVSS 4.8Proof of conceptEPSS 1%ritecms · ritecmsOct 4, 2023
- CVE-2023-4476719Monitor
A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
MediumCVSS 4.8Proof of conceptEPSS 0%ritecms · ritecmsOct 25, 2023
- CVE-2013-531715Monitor
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the m
LowCVSS 3.5Proof of conceptEPSS 3%ritecms · ritecmsAug 20, 2013