Ritecms is a single, modestly represented content-management system whose vulnerability profile centers on input-handling and code-execution flaws endemic to web applications, including cross-site scripting, path traversal, OS command injection, and code injection. The product's disclosures carry an elevated tendency toward public exploit availability, reflecting the accessibility and appeal of web-application targets. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ritecms over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-23934HIGH An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section. | Aug 18, 2020 | 8.8 | 46 | NO | YES |
CVE-2021-46367HIGH RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess confi | Apr 8, 2022 | 7.2 | 38 | NO | NO |
CVE-2024-28623MEDIUM RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section. | Mar 13, 2024 | 6.1 | 32 | NO | YES |
CVE-2013-5316MEDIUM Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator p | Aug 20, 2013 | 6.8 | 32 | NO | YES |
CVE-2025-67174HIGH A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_p | Dec 17, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-67171HIGH Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal. | Dec 17, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-24248MEDIUM RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attack | Apr 12, 2022 | 6.5 | 25 | NO | NO |
CVE-2025-67172HIGH RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function. | Dec 17, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-67173MEDIUM A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request. | Dec 17, 2025 | 6.8 | 23 | NO | NO |
CVE-2022-24247MEDIUM RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attac | Apr 12, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ritecms.
Media articles that mention a CVE ID that affects a product developed by Ritecms — matched by CVE ID, not by vendor name.