CVE-2020-18746: Aitecms

High severity, CVSS 7.2. EPSS: 1.8% chance of exploitation in the next 30 days.

SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".

Affected products

Published 2021-08-18. Last modified 2026-06-17.