Known Vulnerabilities for Kitecms by Kitesky
Listed below are 9 of the newest known vulnerabilities associated with "Kitecms" by "Kitesky".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-28445 json | KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. | 6.5 - MEDIUM | 2022-04-21 | 2022-05-02 |
| CVE-2021-36546 json | Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in ap... | 7.5 - HIGH | 2023-02-03 | 2023-02-10 |
| CVE-2021-31731 json | A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path pa... | 6.5 - MEDIUM | 2021-08-12 | 2021-08-17 |
| CVE-2021-31707 json | Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. | 9.8 - CRITICAL | 2023-04-04 | 2023-04-10 |
| CVE-2021-3267 json | File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile functi... | 7.2 - HIGH | 2023-04-04 | 2023-04-10 |
| CVE-2020-20672 json | An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted... | 7.8 - HIGH | 2021-09-13 | 2021-09-23 |
| CVE-2020-20671 json | A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account. | 8.8 - HIGH | 2021-09-13 | 2021-09-24 |
| CVE-2020-20522 json | Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the register... | 6.1 - MEDIUM | 2023-04-04 | 2023-04-07 |
| CVE-2020-20521 json | Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment ... | 6.1 - MEDIUM | 2023-04-04 | 2023-04-07 |