Openrapid
Openrapid Rapidcms: vulnerabilidades y CVE
Openrapid Rapidcms tiene 17 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses3
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-38930 | Media (6.5) | 0.35% | — | 27 may 2026 | OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie… |
| CVE-2025-64047 | Media (6.1) | 0.18% | — | 24 nov 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php. |
| CVE-2025-64046 | Media (6.1) | 0.18% | — | 17 nov 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php. |
| CVE-2024-45771 | Crítica (9.8) | 0.49% | — | 6 sept 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php. |
| CVE-2024-44839 | Crítica (9.8) | 0.49% | — | 6 sept 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php. |
| CVE-2024-44838 | Crítica (9.8) | 0.50% | — | 6 sept 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php. |
| CVE-2024-8335 | Media (5.3) | 0.59% | — | 30 ago 2024 | A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql… |
| CVE-2024-8331 | Media (5.3) | 0.58% | — | 30 ago 2024 | A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. The manipulation of the argument username leads to… |
| CVE-2023-5262 | Alta (8.8) | 0.78% | — | 29 sept 2023 | A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the file /admin/config/uploadicon.php. The manipulation of the argument… |
| CVE-2023-5258 | Crítica (9.8) | 0.73% | — | 29 sept 2023 | A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is… |
| CVE-2023-5033 | Alta (7.2) | 0.67% | — | 18 sept 2023 | A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /admin/category/cate-edit-run.php. The manipulation of the argument id leads to sql injection.… |
| CVE-2023-5032 | Alta (7.2) | 0.62% | — | 18 sept 2023 | A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/article/article-edit-run.php. The manipulation of the… |
| CVE-2023-5031 | Media (6.5) | 0.52% | — | 18 sept 2023 | A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/article/article-add.php. The manipulation of the… |
| CVE-2023-4448 | Crítica (9.8) | 0.66% | — | 21 ago 2023 | A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads… |
| CVE-2023-4447 | Crítica (9.8) | 0.64% | — | 21 ago 2023 | A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknown code of the file admin/article-chat.php. The manipulation of the argument id leads to sql… |
| CVE-2023-4446 | Crítica (9.8) | 0.74% | — | 21 ago 2023 | A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file template/default/category.php. The manipulation of the argument id leads to sql… |
| CVE-2023-3852 | Alta (7.2) | 25% | — | 23 jul 2023 | A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/upload.php. The manipulation of the argument file leads to… |