Vendorsthedigitalcraftatomcms2.0
Vulnerabilities

thedigitalcraft AtomCMS 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-24223
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
Published 2022-02-01 · Modified
9.81 PoCEPSS 0.620
CVE-2022-25487
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
Published 2022-03-15 · Modified
9.8EPSS 0.538
CVE-2022-25488
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
Published 2022-03-15 · Modified
9.8EPSS 0.071
CVE-2022-28032
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
Published 2022-04-12 · Modified
9.8EPSS 0.059
CVE-2022-28033
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
Published 2022-04-12 · Modified
9.8EPSS 0.053
CVE-2022-28034
AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php
Published 2022-04-12 · Modified
9.8EPSS 0.014
CVE-2022-28035
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php
Published 2022-04-12 · Modified
9.8EPSS 0.014
CVE-2022-28036
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php
Published 2022-04-12 · Modified
9.8EPSS 0.014
CVE-2023-53975
Atom CMS 2.0 Unauthenticated SQL Injection via Admin Index Page
Published 2025-12-22 · Modified
9.3EPSS 0.005
CVE-2014-4852
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.
Published 2014-07-10 · Modified
7.51 PoCEPSS 0.022
CVE-2022-25489
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
Published 2022-03-15 · Modified
5.4EPSS 0.015