📦 Elite Cms

by Elitecms

🔍 What is Elite Cms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-30808

CRITICAL CVSS 9.8 Jun 2, 2022

EliteCMS 1.0.1 contains a critical vulnerability in the admin/manage_uploads.php file that allows authenticated attackers to upload malicious files and execute arbitrary code on the server. This affec...

CVE-2022-30810

CRITICAL CVSS 9.8 Jun 2, 2022

EliteCMS v1.01 contains a SQL injection vulnerability in the admin/edit_post.php endpoint that allows attackers to execute arbitrary SQL commands. This affects all installations of EliteCMS v1.01 with...

CVE-2022-30814

CRITICAL CVSS 9.8 Jun 2, 2022

EliteCMS v1.01 contains a SQL injection vulnerability in the /admin/add_sidebar.php endpoint that allows attackers to execute arbitrary SQL commands. This affects all installations of EliteCMS v1.01, ...

CVE-2022-30816

CRITICAL CVSS 9.8 Jun 2, 2022

CVE-2022-30816 is a critical SQL injection vulnerability in elitecms 1.01 that allows attackers to execute arbitrary SQL commands via the /admin/edit_sidebar.php endpoint. This affects all installatio...

CVE-2021-46093

CRITICAL CVSS 9.8 Feb 1, 2022

eliteCMS v1.0 has an insecure permissions vulnerability in manage_uploads.php that allows attackers to bypass authentication and access administrative file upload functions. This affects all installat...

CVE-2022-24219

CRITICAL CVSS 9.8 Feb 1, 2022

CVE-2022-24219 is a SQL injection vulnerability in eliteCMS v1.0 that allows attackers to execute arbitrary SQL commands via the /admin/edit_page.php endpoint. This affects all installations of eliteC...

CVE-2022-24221

CRITICAL CVSS 9.8 Feb 1, 2022

CVE-2022-24221 is a SQL injection vulnerability in eliteCMS v1.0 that allows attackers to execute arbitrary SQL commands via the /admin/functions/functions.php endpoint. This affects all installations...

CVE-2023-42331

HIGH CVSS 8.8 Sep 20, 2023

This vulnerability in EliteCMS v1.01 allows remote attackers to upload arbitrary files through the manage_uploads.php component, potentially leading to remote code execution. Any organization using th...