Known Vulnerabilities for products from Elitecms
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Elitecms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-42331 json | A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php c... | 8.8 - HIGH | 2023-09-20 | 2023-10-13 |
| CVE-2022-40361 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2024-01-11 | 2024-01-16 |
| CVE-2022-30816 json | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30815 json | elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30814 json | elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30813 json | elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30810 json | elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30809 json | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30808 json | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30804 json | elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=. | 6.5 - MEDIUM | 2022-06-02 | 2023-08-08 |
| CVE-2022-24222 json | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | 9.8 - CRITICAL | 2022-02-01 | 2022-02-02 |
| CVE-2022-24221 json | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | 9.8 - CRITICAL | 2022-02-01 | 2022-02-02 |
| CVE-2022-24220 json | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | 9.8 - CRITICAL | 2022-02-01 | 2022-02-02 |
| CVE-2022-24219 json | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | 9.8 - CRITICAL | 2022-02-01 | 2022-02-02 |
| CVE-2022-24218 json | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | 9.1 - CRITICAL | 2022-02-01 | 2022-02-05 |
| CVE-2021-46093 json | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. | 9.8 - CRITICAL | 2022-02-01 | 2022-02-02 |
| CVE-2018-12250 json | An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL injection... | 7.2 - HIGH | 2019-07-03 | 2019-07-05 |
| CVE-2008-4046 json | SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the pa... | Not Provided | 2008-09-11 | 2026-04-23 |
Known software with vulnerabilities from Elitecms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Elitecms | Elite Cms | 2.01 |