CVE-2025-67174
- EPSS 0.17%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:19:07
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component
CVE-2025-67171
- EPSS 0.77%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:18:40
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.
CVE-2025-67168
- EPSS 0.01%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:18:16
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
CVE-2025-67173
- EPSS 0.03%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:18:50
A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request.
CVE-2025-67170
- EPSS 0.09%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:18:29
A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload.
CVE-2025-67172
- EPSS 0.55%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:18:00
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
CVE-2024-28623
- EPSS 0.6%
- Veröffentlicht 13.03.2024 08:15:43
- Zuletzt bearbeitet 16.04.2025 15:33:39
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
CVE-2023-44767
- EPSS 0.16%
- Veröffentlicht 25.10.2023 18:17:32
- Zuletzt bearbeitet 21.11.2024 08:26:01
A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
CVE-2023-43877
- EPSS 0.15%
- Veröffentlicht 04.10.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:24:56
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu.
CVE-2023-43879
- EPSS 0.22%
- Veröffentlicht 28.09.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 08:24:57
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu.