Записи ritecms
17 опубликованных записей вендора ritecms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-23934Proof of concept | An issue was discovered in RiteCMS 2.2.1.ritecms · ritecms · CWE-78 | Высокая8,8 | — | 16,0 % | 18 авг. 2020 г. |
37Наблюдать | CVE-2021-46367Эксплойта нет | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.ritecms · ritecms · CWE-434 | Высокая7,2 | — | 29,7 % | 8 апр. 2022 г. |
32Наблюдать | CVE-2022-24248Эксплойта нет | RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.ritecms · ritecms · CWE-22 | Средняя6,5 | — | 21,0 % | 12 апр. 2022 г. |
30Наблюдать | CVE-2025-67174Эксплойта нет | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal ritecms · ritecms · CWE-22 | Высокая7,5 | — | 1,3 % | 17 дек. 2025 г. |
30Наблюдать | CVE-2025-67171Эксплойта нет | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.ritecms · ritecms · CWE-22 | Высокая7,5 | — | 0,8 % | 17 дек. 2025 г. |
28Наблюдать | CVE-2013-5316Proof of concept | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for ritecms · ritecms · CWE-352 | Средняя6,8 | — | 2,3 % | 20 авг. 2013 г. |
28Наблюдать | CVE-2025-67172Эксплойта нет | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.ritecms · ritecms · CWE-78 | Высокая7,2 | — | 0,9 % | 17 дек. 2025 г. |
27Наблюдать | CVE-2022-24247Эксплойта нет | RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.ritecms · ritecms · CWE-22 | Средняя6,5 | — | 4,2 % | 12 апр. 2022 г. |
27Наблюдать | CVE-2025-67173Эксплойта нет | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages viaritecms · ritecms · CWE-352 | Средняя6,8 | — | 0,2 % | 17 дек. 2025 г. |
24Наблюдать | CVE-2024-28623Proof of concept | RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.ritecms · ritecms · CWE-79 | Средняя6,1 | — | 1,3 % | 13 мар. 2024 г. |
24Наблюдать | CVE-2025-67170Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user'sritecms · ritecms · CWE-20 | Средняя6,1 | — | 0,3 % | 17 дек. 2025 г. |
21Наблюдать | CVE-2023-43878Proof of concept | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload inritecms · ritecms · CWE-79 | Средняя5,4 | — | 0,5 % | 28 сент. 2023 г. |
21Наблюдать | CVE-2025-67168Эксплойта нет | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.ritecms · ritecms · CWE-916 | Средняя5,3 | — | 0,1 % | 17 дек. 2025 г. |
19Наблюдать | CVE-2023-43879Proof of concept | Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Gritecms · ritecms · CWE-79 | Средняя4,8 | — | 0,5 % | 28 сент. 2023 г. |
19Наблюдать | CVE-2023-43877Proof of concept | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted inritecms · ritecms · CWE-79 | Средняя4,8 | — | 0,5 % | 4 окт. 2023 г. |
19Наблюдать | CVE-2023-44767Proof of concept | A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.ritecms · ritecms · CWE-79 | Средняя4,8 | — | 0,5 % | 25 окт. 2023 г. |
15Наблюдать | CVE-2013-5317Proof of concept | Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mritecms · ritecms · CWE-79 | Низкая3,5 | — | 2,6 % | 20 авг. 2013 г. |
- CVE-2020-2393440В плане
An issue was discovered in RiteCMS 2.2.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 16 %ritecms · ritecms18 авг. 2020 г.
- CVE-2021-4636737Наблюдать
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.
ВысокаяCVSS 7,2Эксплойта нетEPSS 30 %ritecms · ritecms8 апр. 2022 г.
- CVE-2022-2424832Наблюдать
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.
СредняяCVSS 6,5Эксплойта нетEPSS 21 %ritecms · ritecms12 апр. 2022 г.
- CVE-2025-6717430Наблюдать
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ritecms · ritecms17 дек. 2025 г.
- CVE-2025-6717130Наблюдать
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ritecms · ritecms17 дек. 2025 г.
- CVE-2013-531628Наблюдать
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for
СредняяCVSS 6,8Proof of conceptEPSS 2 %ritecms · ritecms20 авг. 2013 г.
- CVE-2025-6717228Наблюдать
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ritecms · ritecms17 дек. 2025 г.
- CVE-2022-2424727Наблюдать
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.
СредняяCVSS 6,5Эксплойта нетEPSS 4 %ritecms · ritecms12 апр. 2022 г.
- CVE-2025-6717327Наблюдать
A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via
СредняяCVSS 6,8Эксплойта нетEPSS 0 %ritecms · ritecms17 дек. 2025 г.
- CVE-2024-2862324Наблюдать
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
СредняяCVSS 6,1Proof of conceptEPSS 1 %ritecms · ritecms13 мар. 2024 г.
- CVE-2025-6717024Наблюдать
A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's
СредняяCVSS 6,1Эксплойта нетEPSS 0 %ritecms · ritecms17 дек. 2025 г.
- CVE-2023-4387821Наблюдать
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload in
СредняяCVSS 5,4Proof of conceptEPSS 1 %ritecms · ritecms28 сент. 2023 г.
- CVE-2025-6716821Наблюдать
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ritecms · ritecms17 дек. 2025 г.
- CVE-2023-4387919Наблюдать
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the G
СредняяCVSS 4,8Proof of conceptEPSS 1 %ritecms · ritecms28 сент. 2023 г.
- CVE-2023-4387719Наблюдать
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in
СредняяCVSS 4,8Proof of conceptEPSS 1 %ritecms · ritecms4 окт. 2023 г.
- CVE-2023-4476719Наблюдать
A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
СредняяCVSS 4,8Proof of conceptEPSS 0 %ritecms · ritecms25 окт. 2023 г.
- CVE-2013-531715Наблюдать
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the m
НизкаяCVSS 3,5Proof of conceptEPSS 3 %ritecms · ritecms20 авг. 2013 г.