📦 Cms Made Simple

by Cmsmadesimple

🔍 What is Cms Made Simple?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-1527

CRITICAL CVSS 9.8 Mar 12, 2024

This vulnerability allows authenticated users in CMS Made Simple to upload malicious files that bypass security filters, potentially leading to remote code execution via webshells. It affects version ...

CVE-2024-1529

HIGH CVSS 7.4 Mar 12, 2024

CMS Made Simple 2.2.14 has a cross-site scripting vulnerability in the admin user creation page that allows attackers to inject malicious JavaScript. This could enable session hijacking when authentic...

CVE-2024-27622

HIGH CVSS 7.2 Mar 5, 2024

This CVE describes a remote code execution vulnerability in CMS Made Simple's User Defined Tags module. Authenticated administrators can inject arbitrary PHP code due to insufficient input sanitizatio...

CVE-2023-36969

HIGH CVSS 8.8 Jul 6, 2023

CMS Made Simple v2.2.17 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious files and execute arbitrary commands on the server. This affects any system...

CVE-2021-28999

HIGH CVSS 8.8 May 8, 2023

This SQL injection vulnerability in CMS Made Simple allows remote attackers to execute arbitrary SQL commands via the m1_sortby parameter in the News module admin interface. Successful exploitation co...

CVE-2022-23906

HIGH CVSS 7.2 Feb 28, 2022

CMS Made Simple v2.2.15 contains a remote command execution vulnerability in the upload avatar function. Attackers can execute arbitrary commands on the server by uploading a specially crafted image f...

CVE-2019-9060

HIGH CVSS 7.5 Sep 17, 2021

This vulnerability in CMS Made Simple allows unauthenticated attackers to perform path traversal attacks, potentially reading arbitrary files on the server. It affects CMS Made Simple installations us...