ritecms kayıtları
ritecms üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-23934Kavram kanıtı | An issue was discovered in RiteCMS 2.2.1.ritecms · ritecms · CWE-78 | Yüksek8,8 | — | %16,0 | 18 Ağu 2020 |
37İzleyin | CVE-2021-46367İstismar yok | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.ritecms · ritecms · CWE-434 | Yüksek7,2 | — | %29,7 | 8 Nis 2022 |
32İzleyin | CVE-2022-24248İstismar yok | RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.ritecms · ritecms · CWE-22 | Orta6,5 | — | %21,0 | 12 Nis 2022 |
30İzleyin | CVE-2025-67174İstismar yok | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal ritecms · ritecms · CWE-22 | Yüksek7,5 | — | %1,3 | 17 Ara 2025 |
30İzleyin | CVE-2025-67171İstismar yok | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.ritecms · ritecms · CWE-22 | Yüksek7,5 | — | %0,8 | 17 Ara 2025 |
28İzleyin | CVE-2013-5316Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for ritecms · ritecms · CWE-352 | Orta6,8 | — | %2,3 | 20 Ağu 2013 |
28İzleyin | CVE-2025-67172İstismar yok | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.ritecms · ritecms · CWE-78 | Yüksek7,2 | — | %0,9 | 17 Ara 2025 |
27İzleyin | CVE-2022-24247İstismar yok | RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.ritecms · ritecms · CWE-22 | Orta6,5 | — | %4,2 | 12 Nis 2022 |
27İzleyin | CVE-2025-67173İstismar yok | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages viaritecms · ritecms · CWE-352 | Orta6,8 | — | %0,2 | 17 Ara 2025 |
24İzleyin | CVE-2024-28623Kavram kanıtı | RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.ritecms · ritecms · CWE-79 | Orta6,1 | — | %1,3 | 13 Mar 2024 |
24İzleyin | CVE-2025-67170İstismar yok | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user'sritecms · ritecms · CWE-20 | Orta6,1 | — | %0,3 | 17 Ara 2025 |
21İzleyin | CVE-2023-43878Kavram kanıtı | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload inritecms · ritecms · CWE-79 | Orta5,4 | — | %0,5 | 28 Eyl 2023 |
21İzleyin | CVE-2025-67168İstismar yok | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.ritecms · ritecms · CWE-916 | Orta5,3 | — | %0,1 | 17 Ara 2025 |
19İzleyin | CVE-2023-43879Kavram kanıtı | Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Gritecms · ritecms · CWE-79 | Orta4,8 | — | %0,5 | 28 Eyl 2023 |
19İzleyin | CVE-2023-43877Kavram kanıtı | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted inritecms · ritecms · CWE-79 | Orta4,8 | — | %0,5 | 4 Eki 2023 |
19İzleyin | CVE-2023-44767Kavram kanıtı | A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.ritecms · ritecms · CWE-79 | Orta4,8 | — | %0,5 | 25 Eki 2023 |
15İzleyin | CVE-2013-5317Kavram kanıtı | Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mritecms · ritecms · CWE-79 | Düşük3,5 | — | %2,6 | 20 Ağu 2013 |
- CVE-2020-2393440Planlayın
An issue was discovered in RiteCMS 2.2.1.
YüksekCVSS 8,8Kavram kanıtıEPSS %16ritecms · ritecms18 Ağu 2020
- CVE-2021-4636737İzleyin
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.
YüksekCVSS 7,2İstismar yokEPSS %30ritecms · ritecms8 Nis 2022
- CVE-2022-2424832İzleyin
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.
OrtaCVSS 6,5İstismar yokEPSS %21ritecms · ritecms12 Nis 2022
- CVE-2025-6717430İzleyin
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal
YüksekCVSS 7,5İstismar yokEPSS %1ritecms · ritecms17 Ara 2025
- CVE-2025-6717130İzleyin
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.
YüksekCVSS 7,5İstismar yokEPSS %1ritecms · ritecms17 Ara 2025
- CVE-2013-531628İzleyin
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for
OrtaCVSS 6,8Kavram kanıtıEPSS %2ritecms · ritecms20 Ağu 2013
- CVE-2025-6717228İzleyin
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
YüksekCVSS 7,2İstismar yokEPSS %1ritecms · ritecms17 Ara 2025
- CVE-2022-2424727İzleyin
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.
OrtaCVSS 6,5İstismar yokEPSS %4ritecms · ritecms12 Nis 2022
- CVE-2025-6717327İzleyin
A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via
OrtaCVSS 6,8İstismar yokEPSS %0ritecms · ritecms17 Ara 2025
- CVE-2024-2862324İzleyin
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
OrtaCVSS 6,1Kavram kanıtıEPSS %1ritecms · ritecms13 Mar 2024
- CVE-2025-6717024İzleyin
A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's
OrtaCVSS 6,1İstismar yokEPSS %0ritecms · ritecms17 Ara 2025
- CVE-2023-4387821İzleyin
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload in
OrtaCVSS 5,4Kavram kanıtıEPSS %1ritecms · ritecms28 Eyl 2023
- CVE-2025-6716821İzleyin
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
OrtaCVSS 5,3İstismar yokEPSS %0ritecms · ritecms17 Ara 2025
- CVE-2023-4387919İzleyin
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the G
OrtaCVSS 4,8Kavram kanıtıEPSS %1ritecms · ritecms28 Eyl 2023
- CVE-2023-4387719İzleyin
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in
OrtaCVSS 4,8Kavram kanıtıEPSS %1ritecms · ritecms4 Eki 2023
- CVE-2023-4476719İzleyin
A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
OrtaCVSS 4,8Kavram kanıtıEPSS %0ritecms · ritecms25 Eki 2023
- CVE-2013-531715İzleyin
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the m
DüşükCVSS 3,5Kavram kanıtıEPSS %3ritecms · ritecms20 Ağu 2013