Elitecms operates a content management system whose vulnerability profile skews strongly toward critical-severity outcomes, driven by recurrent input-handling and file-management weaknesses including SQL injection, cross-site scripting, path traversal, unrestricted file uploads, and improper default permissions. The vendor's disclosures moderate tendency toward public exploit availability reflects the web-application attack surface and the accessibility of CMS platforms to both researchers and adversaries. Defenders should treat updates to this product as high-priority given the severity tendency and broad exposure of content management systems; live exploitation status and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elitecms over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24218CRITICAL An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | Feb 1, 2022 | 9.1 | 37 | NO | NO |
CVE-2022-30810CRITICAL elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30808CRITICAL elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-24222CRITICAL eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | Feb 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24220CRITICAL eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | Feb 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24219CRITICAL eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | Feb 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-46093CRITICAL eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. | Feb 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-30816CRITICAL elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | Jun 2, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-30815CRITICAL elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | Jun 2, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-30814CRITICAL elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | Jun 2, 2022 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elitecms.
Media articles that mention a CVE ID that affects a product developed by Elitecms — matched by CVE ID, not by vendor name.