← Back

Atomcms

atomcms

Vendor: Thedigitalcraft • 11 CVEs

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Thedigitalcraft
1Atomcms
Jan 5, 2026
Dec 22, 2025
9.3 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' paramet...Show more
Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.Show less
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Apr 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Apr 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Apr 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Apr 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Apr 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
1Thedigitalcraft
1Atomcms
Nov 21, 2024
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
1Thedigitalcraft
1Atomcms
May 6, 2026
Jul 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.