Kitesky develops KiteCMS, a web content management system whose vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity. The recurring weakness classes—unrestricted file uploads, cross-site scripting, cross-site request forgery, exposed file access, and path traversal—reflect the input-handling and access-control demands of web application architecture and the exposure inherent to internet-facing CMS platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kitesky over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31707CRITICAL Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. | Apr 4, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-20671HIGH A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account. | Sep 13, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-20672HIGH An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file. | Sep 13, 2021 | 7.8 | 26 | NO | NO |
CVE-2021-36546HIGH Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL. | Feb 3, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-3267HIGH File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function. | Apr 4, 2023 | 7.2 | 23 | NO | NO |
CVE-2022-28445MEDIUM KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. | Apr 21, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-31731MEDIUM A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP | Aug 12, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-20522MEDIUM Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter. | Apr 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2020-20521MEDIUM Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter. | Apr 4, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kitesky.
Media articles that mention a CVE ID that affects a product developed by Kitesky — matched by CVE ID, not by vendor name.