CVE-2020-18746: Aitecms
High severity, CVSS 7.2. EPSS: 1.8% chance of exploitation in the next 30 days.
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
Affected products
- Aitecms Aitecms: version 1.0 only
Published 2021-08-18. Last modified 2026-06-17.