cmsmadesimple

158 tracked vulnerabilities.

CVE-2018-7893 MEDIUM
CMS Made Simple 2.2.6 - Stored Cross-Site Scripting via Metadata Parameter
Mar 12, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-7448 HIGH
CMS Made Simple 2.1.6 - Remote Code Execution via Timezone Parameter in Installation
Feb 26, 2018
CVSS 7.5
EPSS 0.42
CVE-2018-5965 MEDIUM
CMS Made Simple 2.2.5 - Cross-Site Scripting via m1_errors Parameter
Jan 25, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-5964 MEDIUM
CMS Made Simple 2.2.5 - Cross-Site Scripting via m1_messages Parameter
Jan 25, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-5963 MEDIUM
CMS Made Simple 2.2.5 - Stored Cross-Site Scripting via Bookmark Title Parameter
Jan 25, 2018
CVSS 4.8
EPSS 0.00
CVE-2017-1000454 HIGH
CMS Made Simple <2.2.1 - Code Injection
Jan 02, 2018
CVSS 7.8
EPSS 0.00
CVE-2017-1000453 CRITICAL
CMS Made Simple <2.1.6-2.2 - Code Injection
Jan 02, 2018
CVSS 9.8
EPSS 0.01
CVE-2017-17735 CRITICAL
CMS Made Simple < 2.2.5 - Exposure of Sensitive Information via Cookie Caching
Dec 18, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-17734 CRITICAL
CMS Made Simple < 2.2.5 - Exposure of Sensitive Information via Session Cache
Dec 18, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-16799 MEDIUM
CMS Made Simple 2.2.3.1 - XSS
Nov 12, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-16798 MEDIUM
CMS Made Simple 2.2.3.1 - Cross-Site Scripting via File Upload Extension Bypass
Nov 12, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-16784 MEDIUM
CMS Made Simple 2.2.2 - Reflected Cross-Site Scripting via cntnt01detailtemplate Parameter
Nov 10, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-16783 CRITICAL
CMS Made Simple 2.1.6 - Server-Side Template Injection via cntnt01detailtemplate Parameter
Nov 10, 2017
CVSS 9.8
EPSS 0.10
CVE-2017-11405 MEDIUM
CMS Made Simple 2.2.2 - Authenticated Arbitrary File Upload via FilePicker Type Manipulation
Jul 18, 2017
CVSS 4.9
EPSS 0.00
CVE-2017-11404 MEDIUM
CMS Made Simple 2.2.2 - Authenticated Arbitrary File Upload via FileManager
Jul 18, 2017
CVSS 4.9
EPSS 0.00
CVE-2017-9668 MEDIUM
CMS Made Simple 2.1.6 - Stored Cross-Site Scripting via Group Description Parameter
Jun 18, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-8912 HIGH
CMS Made Simple 2.1.6 - Authenticated PHP Code Execution via Edit User Tag
May 12, 2017
CVSS 7.2
EPSS 0.04
CVE-2017-7257 MEDIUM
CMS Made Simple 2.1.6 - Authenticated Stored Cross-Site Scripting via News Article m1_content Parameter
Mar 24, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-7256 MEDIUM
CMS Made Simple 2.1.6 - Authenticated Stored Cross-Site Scripting via News Article Summary Parameter
Mar 24, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-7255 MEDIUM
CMS Made Simple 2.1.6 - Authenticated Stored Cross-Site Scripting via News Article m1_title Parameter
Mar 24, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-6556 MEDIUM
CMS Made Simple 2.1.6 - Authenticated Stored Cross-Site Scripting via Global Metadata Field
Mar 09, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-6555 MEDIUM
CMS Made Simple 2.1.6 - Authenticated Cross-Site Scripting via m1_description Parameter
Mar 09, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-6072 MEDIUM
CMS Made Simple Form Builder < 0.8.1.6 - Information Disclosure via Default Admin
Feb 21, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-6071 MEDIUM
CMS Made Simple Form Builder < 0.8.1.6 - Information Disclosure via ExportXML
Feb 21, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-6070 CRITICAL
CMS Made Simple Form Builder < 0.8.1.6 - Remote Code Execution via cntnt01fbrp_forma_form_template Parameter
Feb 21, 2017
CVSS 9.8
EPSS 0.01