Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-67171 Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal. Ritecms No fix yet Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-67174 A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the ad… Ritecms No fix yet Fix from $1,9502025-12-17 MEDIUM 6.8 CVE-2025-67173 A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafte… Ritecms No fix yet Fix from $1,6002025-12-17 MEDIUM 6.1 CVE-2025-67170 A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser … Ritecms No fix yet Fix from $1,6002025-12-17 MEDIUM 5.3 CVE-2025-67168 RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. Ritecms No fix yet Fix from $1,6002025-12-17 HIGH 7.2 CVE-2025-67172 RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function. Ritecms No fix yet Fix from $1,9502025-12-17 MEDIUM 6.1 CVE-2024-28623 RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section. Ritecms No fix yet Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2023-43878 Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Ma… Ritecms No fix yet Fix from $1,6002023-09-28 HIGH 8.8 CVE-2020-23934EPSS 16% An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager… Ritecms No fix yet Fix from $1,9502020-08-18 MEDIUM 6.8 CVE-2013-5316 Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests … Ritecms No fix yet Fix from $1,6002013-08-20