cmsmadesimple

158 tracked vulnerabilities.

CVE-2020-10681 MEDIUM
CMS Made Simple 2.2.13 - Stored XSS
Mar 20, 2020
CVSS 5.4
EPSS 0.00
CVE-2019-9060 HIGH
CMS Made Simple 2.2.8 - Unauthenticated Path Traversal and Arbitrary File Read via CGExtensions Module
Sep 17, 2021
CVSS 7.5
EPSS 0.00
CVE-2019-17630 MEDIUM
CMS Made Simple 2.2.11 - Stored Cross-Site Scripting via News Article Image Filename
Oct 16, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-17629 MEDIUM
CMS Made Simple 2.2.11 - Stored Cross-Site Scripting via Image Filename Upload
Oct 16, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-17226 MEDIUM
CMS Made Simple 2.2.11 - Stored Cross-Site Scripting via Module Manager Search Term Field
Oct 06, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-1010290 MEDIUM NUCLEI
Babel All - Open Redirect
Jul 16, 2019
CVSS 6.1
EPSS 0.24
CVE-2019-11226 MEDIUM
CMS Made Simple 2.2.10 - Stored Cross-Site Scripting via m1_name Parameter
Jun 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-11513 MEDIUM
CMS Made Simple < 2.2.10 - Reflected Cross-Site Scripting via File Manager Rename Action
Apr 25, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-9056 HIGH
CMS Made Simple 2.2.8 - Authenticated Object Injection via FrontEndUsers Module
Apr 11, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-10107 MEDIUM
CMS Made Simple 2.2.10 - Stored Cross-Site Scripting via My Account Email Address Field
Mar 26, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10106 MEDIUM
CMS Made Simple 2.2.10 - Stored Cross-Site Scripting via News Module Category Name Field
Mar 26, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10105 MEDIUM
CMS Made Simple 2.2.10 - Stored Cross-Site Scripting in Layout Design Manager Name Field
Mar 26, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-9061 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation
Mar 26, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-9059 HIGH
CMS Made Simple < 2.2.8 - Authenticated Command Injection via Mail Settings
Mar 26, 2019
CVSS 7.2
EPSS 0.07
CVE-2019-9058 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via sel_groups Parameter
Mar 26, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-9057 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via FilePicker Module
Mar 26, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-9055 HIGH
CMS Made Simple < 2.2.8 - Authenticated Remote Code Execution via m1_allparms Deserialization
Mar 26, 2019
CVSS 8.8
EPSS 0.32
CVE-2019-9053 HIGH
CMS Made Simple 2.2.8 - Unauthenticated Blind SQL Injection via News Module m1_idlist Parameter
Mar 26, 2019
CVSS 8.1
EPSS 0.93
CVE-2019-10017 MEDIUM
CMS Made Simple 2.2.10 - Stored Cross-Site Scripting via File Picker Name Field
Mar 24, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-9693 HIGH
CMS Made Simple < 2.2.10 - Authenticated SQL Injection via show_id and picture_id Parameters
Mar 11, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-9692 MEDIUM
CMS Made Simple < 2.2.10 - Unrestricted File Upload via Watermark Image Extension Bypass
Mar 11, 2019
CVSS 6.5
EPSS 0.59
CVE-2018-20464 MEDIUM
CMS Made Simple 2.2.8 - Reflected Cross-Site Scripting in Admin MyAccount Page
Dec 25, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-19597 MEDIUM
CMS Made Simple 2.2.8 - Stored Cross-Site Scripting via SVG Upload
Dec 19, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-18271 MEDIUM
CMS Made Simple 2.2.7 - Cross-Site Scripting via m1_extra Parameter
Oct 12, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-18270 MEDIUM
CMS Made Simple 2.2.7 - Stored Cross-Site Scripting via m1_news_url Parameter
Oct 12, 2018
CVSS 6.1
EPSS 0.00