Перейти к содержимому
Noroxi

Записи ritecms

17 опубликованных записей вендора ritecms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

17 записей
  • CVE-2020-23934
    40В плане

    An issue was discovered in RiteCMS 2.2.1.

    ВысокаяCVSS 8,8Proof of conceptEPSS 16 %

    ritecms · ritecms18 авг. 2020 г.

  • CVE-2021-46367
    37Наблюдать

    RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 30 %

    ritecms · ritecms8 апр. 2022 г.

  • CVE-2022-24248
    32Наблюдать

    RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.

    СредняяCVSS 6,5Эксплойта нетEPSS 21 %

    ritecms · ritecms12 апр. 2022 г.

  • CVE-2025-67174
    30Наблюдать

    A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ritecms · ritecms17 дек. 2025 г.

  • CVE-2025-67171
    30Наблюдать

    Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ritecms · ritecms17 дек. 2025 г.

  • CVE-2013-5316
    28Наблюдать

    Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    ritecms · ritecms20 авг. 2013 г.

  • CVE-2025-67172
    28Наблюдать

    RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    ritecms · ritecms17 дек. 2025 г.

  • CVE-2022-24247
    27Наблюдать

    RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.

    СредняяCVSS 6,5Эксплойта нетEPSS 4 %

    ritecms · ritecms12 апр. 2022 г.

  • CVE-2025-67173
    27Наблюдать

    A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    ritecms · ritecms17 дек. 2025 г.

  • CVE-2024-28623
    24Наблюдать

    RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    ritecms · ritecms13 мар. 2024 г.

  • CVE-2025-67170
    24Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    ritecms · ritecms17 дек. 2025 г.

  • CVE-2023-43878
    21Наблюдать

    Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload in

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    ritecms · ritecms28 сент. 2023 г.

  • CVE-2025-67168
    21Наблюдать

    RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ritecms · ritecms17 дек. 2025 г.

  • CVE-2023-43879
    19Наблюдать

    Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the G

    СредняяCVSS 4,8Proof of conceptEPSS 1 %

    ritecms · ritecms28 сент. 2023 г.

  • CVE-2023-43877
    19Наблюдать

    Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in

    СредняяCVSS 4,8Proof of conceptEPSS 1 %

    ritecms · ritecms4 окт. 2023 г.

  • CVE-2023-44767
    19Наблюдать

    A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

    СредняяCVSS 4,8Proof of conceptEPSS 0 %

    ritecms · ritecms25 окт. 2023 г.

  • CVE-2013-5317
    15Наблюдать

    Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the m

    НизкаяCVSS 3,5Proof of conceptEPSS 3 %

    ritecms · ritecms20 авг. 2013 г.