← Vulnerability feed

Vulnerability record · CVE-2022-28033 · published 12 April 2022

CVE-2022-28033: Thedigitalcraft atomcms sql injection vulnerability

Thedigitalcraft · Atomcms

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

9.8 CVSS 3.1 Critical EPSS 5.3% · top 7.7% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/thedigicraft/Atom.CMS/issues/259 ExploitIssue TrackingThird Party Advisory
https://github.com/thedigicraft/Atom.CMS/issues/259 ExploitIssue TrackingThird Party Advisory

Track CVE-2022-28033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28032Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.phpEPSS 5.9%9.8CVE-2022-28034Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.phpEPSS 1.4%9.8CVE-2022-28035Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.phpEPSS 1.4%9.8CVE-2022-28036Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.phpEPSS 1.4%9.8CVE-2022-25487Atom CMS unrestricted file upload in admin/uploads.php leads to RCEAtom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious fil…EPSS 54%analysed9.8CVE-2022-25488Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.EPSS 7.1%9.8CVE-2022-24223AtomCMS admin login SQL injectionAtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit refere…EPSS 62%analysed9.3CVE-2023-53975Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2022-28033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.