Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ritecms HIGH 7.5
CVE-2025-67171

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

No fix yet
Fix from $1,950 2025-12-17
Ritecms HIGH 7.5
CVE-2025-67174

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the ad…

No fix yet
Fix from $1,950 2025-12-17
Ritecms MEDIUM 6.8
CVE-2025-67173

A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafte…

No fix yet
Fix from $1,600 2025-12-17
Ritecms MEDIUM 6.1
CVE-2025-67170

A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser …

No fix yet
Fix from $1,600 2025-12-17
Ritecms MEDIUM 5.3
CVE-2025-67168

RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

No fix yet
Fix from $1,600 2025-12-17
Ritecms HIGH 7.2
CVE-2025-67172

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

No fix yet
Fix from $1,950 2025-12-17
Ritecms MEDIUM 6.1
CVE-2024-28623

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

No fix yet
Fix from $1,600 2024-03-13
Ritecms MEDIUM 5.4
CVE-2023-43878

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Ma…

No fix yet
Fix from $1,600 2023-09-28
Ritecms HIGH 8.8
CVE-2020-23934EPSS 16%

An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager…

No fix yet
Fix from $1,950 2020-08-18
Ritecms MEDIUM 6.8
CVE-2013-5316

Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests …

No fix yet
Fix from $1,600 2013-08-20