Openrapid Rapidcms vulnerabilities
16 known vulnerabilities affecting openrapid/rapidcms.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH4MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-3852P1HIGHCVSS 7.2Exploited≤ 1.3.1v1.3.0+1 more2023-07-23
CVE-2023-3852 [HIGH] CWE-434 CVE-2023-3852: A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This
A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/upload.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch
nvd
CVE-2023-4448P3CRITICALCVSS 9.8v1.3.12023-08-21
CVE-2023-4448 [CRITICAL] CWE-640 CVE-2023-4448: A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The i
nvd
CVE-2023-5262P3HIGHCVSS 8.8v1.3.12023-09-29
CVE-2023-5262 [HIGH] CWE-434 CVE-2023-5262: A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by t
A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the file /admin/config/uploadicon.php. The manipulation of the argument fileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Th
nvd
CVE-2024-8335P3CRITICALCVSS 9.8≤ 1.3.1v1.3.0+1 more2024-08-30
CVE-2024-8335 [CRITICAL] CWE-89 CVE-2024-8335: A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-8331P3CRITICALCVSS 9.8≤ 1.3.1v1.3.0+1 more2024-08-30
CVE-2024-8331 [CRITICAL] CWE-89 CVE-2024-8331: A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. Thi
A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2023-5258P3CRITICALCVSS 9.8v1.3.12023-09-29
CVE-2023-5258 [CRITICAL] CWE-89 CVE-2023-5258: A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an u
A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this v
nvd
CVE-2023-4446P3CRITICALCVSS 9.8v1.3.12023-08-21
CVE-2023-4446 [CRITICAL] CWE-89 CVE-2023-4446: A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affec
A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file template/default/category.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237567.
nvd
CVE-2023-4447P3CRITICALCVSS 9.8v1.3.12023-08-21
CVE-2023-4447 [CRITICAL] CWE-89 CVE-2023-4447: A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerab
A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknown code of the file admin/article-chat.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulner
nvd
CVE-2024-45771P3CRITICALCVSS 9.8v1.3.12024-09-06
CVE-2024-45771 [CRITICAL] CWE-89 CVE-2024-45771: RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter a
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.
nvd
CVE-2024-44839P3CRITICALCVSS 9.8v1.3.12024-09-06
CVE-2024-44839 [CRITICAL] CWE-89 CVE-2024-44839: RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.
nvd
CVE-2024-44838P3CRITICALCVSS 9.8v1.3.12024-09-06
CVE-2024-44838 [CRITICAL] CWE-89 CVE-2024-44838: RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter a
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.
nvd
CVE-2023-5033P3HIGHCVSS 7.2v1.3.12023-09-18
CVE-2023-5033 [HIGH] CWE-89 CVE-2023-5033: A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an u
A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /admin/category/cate-edit-run.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239877 w
nvd
CVE-2023-5032P3HIGHCVSS 7.2v1.3.12023-09-18
CVE-2023-5032 [HIGH] CWE-89 CVE-2023-5032: A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been rated as critical. Affected by th
A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/article/article-edit-run.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The ident
nvd
CVE-2023-5031P3MEDIUMCVSS 6.5v1.3.12023-09-18
CVE-2023-5031 [MEDIUM] CWE-89 CVE-2023-5031: A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been declared as critical. Affected by
A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/article/article-add.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2025-64047P4MEDIUMCVSS 6.1v1.3.12025-11-24
CVE-2025-64047 [MEDIUM] CWE-79 CVE-2025-64047: OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
nvd
CVE-2025-64046P4MEDIUMCVSS 6.1v1.3.12025-11-17
CVE-2025-64046 [MEDIUM] CWE-79 CVE-2025-64046: OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
nvd