← Vulnerability feed

Vulnerability record · CVE-2025-67171 · published 17 December 2025

CVE-2025-67171: Ritecms path traversal vulnerability

RRitecms · Ritecms

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

7.5 CVSS 3.1 High EPSS 0.82% · top 44.6% CWE-22 · Path traversal
7.5CVSS 3.1 base score
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-67171 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-23934Ritecms os command injection vulnerabilityAn issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager…EPSS 16%7.5CVE-2025-67174Ritecms path traversal vulnerabilityA local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the ad…EPSS 1.3%7.2CVE-2025-67172Ritecms os command injection vulnerabilityRiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.EPSS 0.92%7.2CVE-2021-46367Ritecms unrestricted file upload vulnerabilityRiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP fil…EPSS 30%6.8CVE-2025-67173Ritecms cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafte…EPSS 0.19%6.8CVE-2013-5316Ritecms cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests …EPSS 2.3%6.5CVE-2022-24247Ritecms path traversal vulnerabilityRiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerabilit…EPSS 4.2%6.5CVE-2022-24248Ritecms path traversal vulnerabilityRiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2025-67171), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.