KiteskyCVEs & Vulnerabilities

9 CVEs affecting Kitesky products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

kitecms 9
CVE-2021-3267HIGH

File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.

4 Apr 2023
7.2
CVSS
CVE-2021-31707CRITICAL

Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.

4 Apr 2023
9.8
CVSS
CVE-2020-20522MEDIUM

Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter.

4 Apr 2023
6.1
CVSS
CVE-2020-20521MEDIUM

Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.

4 Apr 2023
6.1
CVSS
CVE-2021-36546HIGH

Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.

3 Feb 2023
7.5
CVSS
CVE-2022-28445MEDIUM

KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.

21 Apr 2022
6.5
CVSS
CVE-2020-20672HIGH

An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.

14 Sep 2021
7.8
CVSS
CVE-2020-20671HIGH

A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.

14 Sep 2021
8.8
CVSS
CVE-2021-31731MEDIUM

A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.

13 Aug 2021
6.5
CVSS
← PrevPage 1 / 1Next →