← Vulnerability feed

Vulnerability record · CVE-2022-25489 · published 15 March 2022

CVE-2022-25489: Thedigitalcraft atomcms cross-site scripting vulnerability

Thedigitalcraft · Atomcms

Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.

5.4 CVSS 3.1 Medium EPSS 1.5% · top 27.3% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/thedigicraft/Atom.CMS/issues/258 ExploitIssue TrackingThird Party Advisory
https://github.com/thedigicraft/Atom.CMS/issues/258 ExploitIssue TrackingThird Party Advisory

Track CVE-2022-25489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28035Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.phpEPSS 1.4%9.8CVE-2022-28033Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.phpEPSS 5.3%9.8CVE-2022-28036Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.phpEPSS 1.4%9.8CVE-2022-28034Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.phpEPSS 1.4%9.8CVE-2022-28032Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.phpEPSS 5.9%9.8CVE-2022-25487Atom CMS unrestricted file upload in admin/uploads.php leads to RCEAtom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious fil…EPSS 54%analysed9.8CVE-2022-25488Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.EPSS 7.1%9.8CVE-2022-24223AtomCMS admin login SQL injectionAtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit refere…EPSS 62%analysed

Source: NIST National Vulnerability Database (record CVE-2022-25489), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.