Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/handylulu/RiteCMS

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-67174: n/aCVE-2025-67174
0

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

Join the discussion
CVE-2025-67168: n/aCVE-2025-67168
0

CVE-2025-67168 is a medium severity vulnerability in RiteCMS v3.1.0 where insecure encryption is used to store passwords. This flaw allows attackers to potentially recover user passwords if they gain access to the stored password data, impacting confidentiality but not integrity or availability. The vulnerability requires no authentication or user interaction and can be exploited remotely. While no known exploits are currently reported in the wild, the weakness in password storage practices poses a risk to user credential security. European organizations using RiteCMS v3.1.0 should prioritize remediation to prevent credential compromise. The vulnerability has a CVSS score of 5.

Join the discussion
CVE-2025-67173: n/aCVE-2025-67173
0

CVE-2025-67173 is a Cross-Site Request Forgery (CSRF) vulnerability in RiteCMS version 3.1.0 that allows attackers to create pages arbitrarily by sending crafted POST requests. The vulnerability requires the attacker to have some level of privileges (PR:H) and user interaction (UI:R), but it can lead to high impact on confidentiality, integrity, and availability. Although no known exploits are currently in the wild, the medium severity CVSS score of 6.8 reflects the significant risk posed by this flaw. European organizations using RiteCMS 3.1.0 should prioritize patching or implementing mitigations to prevent unauthorized content injection and potential further exploitation. Countries with higher adoption of RiteCMS or critical web infrastructure relying on it are at greater risk.

Join the discussion
CVE-2025-67170: n/aCVE-2025-67170
0

CVE-2025-67170 is a reflected cross-site scripting (XSS) vulnerability in RiteCMS version 3.1.0 that enables attackers to execute arbitrary code within a user's browser by delivering a crafted payload. This vulnerability requires user interaction, such as clicking a malicious link, and does not require authentication. The vulnerability impacts confidentiality and integrity by potentially exposing sensitive user data or enabling session hijacking, but does not affect availability. The CVSS score is 6.1 (medium severity), reflecting the moderate risk posed by this vulnerability. No known exploits are currently reported in the wild, and no patches have been published yet. European organizations using RiteCMS 3.1.

Join the discussion
CVE-2025-67172: n/aCVE-2025-67172
0

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

Join the discussion
CVE-2024-28623: n/aCVE-2024-28623
0

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/handylulu/RiteCMS
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses