Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ritecms

First CVE: Aug 20, 2013Active for: 13 yearsTotal CVEs: 17
41.7
VTI Score
High

Ritecms is a single, modestly represented content-management system whose vulnerability profile centers on input-handling and code-execution flaws endemic to web applications, including cross-site scripting, path traversal, OS command injection, and code injection. The product's disclosures carry an elevated tendency toward public exploit availability, reflecting the accessibility and appeal of web-application targets. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ritecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2013
12 years ago
Most Recent CVE
Dec 17, 2025
220 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-23934HIGH
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
Aug 18, 20208.846NOYES
CVE-2021-46367HIGH
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess confi
Apr 8, 20227.238NONO
CVE-2024-28623MEDIUM
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
Mar 13, 20246.132NOYES
CVE-2013-5316MEDIUM
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator p
Aug 20, 20136.832NOYES
CVE-2025-67174HIGH
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_p
Dec 17, 20257.526NONO
CVE-2025-67171HIGH
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.
Dec 17, 20257.525NONO
CVE-2022-24248MEDIUM
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attack
Apr 12, 20226.525NONO
CVE-2025-67172HIGH
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
Dec 17, 20257.224NONO
CVE-2025-67173MEDIUM
A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request.
Dec 17, 20256.823NONO
CVE-2022-24247MEDIUM
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attac
Apr 12, 20226.523NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
65%
29%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network15 (88.2%)
Unknown2 (11.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High0 (0.0%)
Unknown2 (11.8%)
User Interaction
None8 (47.1%)
Unknown2 (11.8%)
Required7 (41.2%)
Privileges Required
Low2 (11.8%)
High8 (47.1%)
None5 (29.4%)
Unknown2 (11.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 96th percentile
ExploitDB
4 CVEs
23.5% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ritecms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ritecms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ritecms's Products

View all 1 CNAs →

Top CWEs