CVE Browser

More filters (active)
CVE-2025-67174 HIGH

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_langua…

CVSS 7.5 EPSS 1.32% Dec 17, 2025
CVE-2025-67173 MEDIUM

A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST req…

CVSS 6.8 EPSS 0.19% Dec 17, 2025
CVE-2025-67172 HIGH

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

CVSS 7.2 EPSS 0.92% Dec 17, 2025
CVE-2025-67171 HIGH

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

CVSS 7.5 EPSS 0.82% Dec 17, 2025
CVE-2025-67170 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a craf…

CVSS 6.1 EPSS 0.27% Dec 17, 2025
CVE-2025-67168 MEDIUM

RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

CVSS 5.3 EPSS 0.14% Dec 17, 2025
CVE-2024-28623 MEDIUM

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

CVSS 6.1 EPSS 1.32% Mar 13, 2024
CVE-2023-44767 MEDIUM

A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

CVSS 4.8 EPSS 0.46% Oct 24, 2023
CVE-2023-43877 MEDIUM

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fiel…

CVSS 4.8 EPSS 0.55% Oct 4, 2023
CVE-2023-43879 MEDIUM

Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Block…

CVSS 4.8 EPSS 0.53% Sep 28, 2023
CVE-2023-43878 MEDIUM

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu It…

CVSS 5.4 EPSS 0.53% Sep 28, 2023
CVE-2022-24248 MEDIUM

RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an…

CVSS 6.5 EPSS 20.96% Apr 12, 2022
CVE-2022-24247 MEDIUM

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows a…

CVSS 6.5 EPSS 4.15% Apr 12, 2022
CVE-2021-46367 HIGH

RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypa…

CVSS 7.2 EPSS 29.72% Apr 8, 2022
CVE-2020-23934 HIGH

An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.

CVSS 8.8 EPSS 15.96% Aug 18, 2020
CVE-2013-5317 LOW

Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mode parameter to cm…

CVSS 3.5 EPSS 2.64% Aug 20, 2013
CVE-2013-5316 MEDIUM

Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that chang…

CVSS 6.8 EPSS 2.27% Aug 20, 2013

Showing 1 to 17 CVEs · page 1