cmsmadesimple

158 tracked vulnerabilities.

CVE-2021-40961 HIGH
CMS Made Simple <=2.2.15 - SQL Injection
Jun 09, 2022
CVSS 8.8
EPSS 0.01
CVE-2021-43154 MEDIUM
CMS Made Simple 2.2.15 - Authenticated Stored Cross-Site Scripting via Add Category Name Field
Apr 13, 2022
CVSS 6.1
EPSS 0.00
CVE-2021-28935 MEDIUM
CMS Made Simple 2.2.15 - Authenticated Cross-Site Scripting via Title Field
Mar 30, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-37238 MEDIUM
CMS Made Simple 2.2.15 Stored XSS via SVG File Upload
May 16, 2026
CVSS 6.4
EPSS 0.00
CVE-2020-23481 MEDIUM
CMS Made Simple 2.2.14 - Stored Cross-Site Scripting via Field Definition Text Field
Sep 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-22732 MEDIUM
CMS Made Simple 2.2.14 - Stored Cross-Site Scripting via File Picker
Aug 05, 2021
CVSS 4.8
EPSS 0.00
CVE-2020-23241 MEDIUM
CMS Made Simple 2.2.14 - Cross-Site Scripting via News Article Feature
Jul 26, 2021
CVSS 4.8
EPSS 0.00
CVE-2020-23240 MEDIUM
CMS Made Simple 2.2.14 - Stored Cross-Site Scripting via Content Manager Logic Field
Jul 26, 2021
CVSS 4.8
EPSS 0.00
CVE-2020-36416 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Design Creation Parameter
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36415 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Stylesheet Creation
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36414 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Add Article URL or Extra Fields
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36413 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Maintenance Mode IP Exclusion Parameter
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36412 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Admin Search Text Field
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36411 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Content Editing Settings Parameters
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36410 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via News Submission Email Parameter
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36409 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Add Category Parameter
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36408 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting via Add Shortcut Parameter
Jul 02, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-27377 MEDIUM
CMS Made Simple 2.2.14 - Stored Cross-Site Scripting in Administrator Panel Setting News Module
Jun 01, 2021
CVSS 4.8
EPSS 0.00
CVE-2020-20138 MEDIUM
CMS Made Simple 2.2.4 - Cross-Site Scripting in Showtime2 Slideshow Module
Dec 17, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-24860 MEDIUM
CMS Made Simple 2.2.14 - Authenticated Stored Cross-Site Scripting in Content Manager
Oct 01, 2020
CVSS 5.4
EPSS 0.01
CVE-2020-22842 MEDIUM
CMS Made Simple < 2.2.15 - Cross-Site Scripting via m1_mod Parameter
Sep 30, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-17462 HIGH
CMS Made Simple <2.2.14 - Auth Bypass
Aug 14, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-14926 MEDIUM
CMS Made Simple 2.2.14 - Cross-Site Scripting via Search Term in Module Manager
Jun 19, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-13660 MEDIUM
CMS Made Simple < 2.2.14 - Stored Cross-Site Scripting via File Picker Profile Name
May 28, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-10682 HIGH
CMS Made Simple 2.2.13 - Remote Code Execution via Filemanager .php.jpegd Upload
Mar 20, 2020
CVSS 7.8
EPSS 0.02