← Vulnerability feed

Vulnerability record · CVE-2023-53975 · published 22 December 2025

CVE-2023-53975: Thedigitalcraft atomcms sql injection vulnerability

Thedigitalcraft · Atomcms

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

9.3 CVSS 4.0 Critical EPSS 0.47% · top 61.7% CWE-89 · SQL injection
9.3CVSS 4.0 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-53975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28032Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.phpEPSS 5.9%9.8CVE-2022-28033Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.phpEPSS 5.3%9.8CVE-2022-28034Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.phpEPSS 1.4%9.8CVE-2022-28035Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.phpEPSS 1.4%9.8CVE-2022-28036Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.phpEPSS 1.4%9.8CVE-2022-25487Atom CMS unrestricted file upload in admin/uploads.php leads to RCEAtom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious fil…EPSS 54%analysed9.8CVE-2022-25488Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.EPSS 7.1%9.8CVE-2022-24223AtomCMS admin login SQL injectionAtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit refere…EPSS 62%analysed

Source: NIST National Vulnerability Database (record CVE-2023-53975), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.