cmsmadesimple

158 tracked vulnerabilities.

CVE-2016-7904 HIGH
CMS Made Simple < 2.1.6 - Cross-Site Request Forgery via Admin User Creation
Jan 16, 2017
CVSS 8.0
EPSS 0.01
CVE-2016-2784 MEDIUM
CMS Made Simple 1.x < 1.12.2 and 2.x < 2.1.3 - Cache Poisoning and Cross-Site Scripting via HTTP Host Header
May 26, 2016
CVSS 4.7
EPSS 0.06
CVE-2014-2245
CMS Made Simple < 1.11.10 - Authenticated SQL Injection via News Module sortby Parameter
Mar 05, 2014
EPSS 0.00
CVE-2014-2092
CMS Made Simple 1.11.10 - Cross-Site Scripting via ImageManager Editor Frame Action Parameter
Mar 02, 2014
EPSS 0.00
CVE-2014-0334
CMS Made Simple - Authenticated Stored Cross-Site Scripting via Multiple Admin Parameters
Mar 02, 2014
EPSS 0.01
CVE-2013-3929
CMS Made Simple 1.11.9 - Authenticated Cross-Site Scripting via editevent.php Handler Parameter
Dec 09, 2013
EPSS 0.00
CVE-2013-4167
CMS Made Simple < 1.11.7 - Cross-Site Scripting
Oct 11, 2013
EPSS 0.00
CVE-2012-6064
CMS Made Simple < 1.11.2.1 - Authenticated Path Traversal via deld Parameter
Dec 03, 2012
EPSS 0.01
CVE-2012-5450
CMS Made Simple < 1.11.2 - Cross-Site Request Forgery via deld Parameter
Dec 03, 2012
EPSS 0.00
CVE-2012-1992
CMS Made Simple < 1.10.3 - Cross-Site Scripting via Email Parameter
Apr 11, 2012
EPSS 0.00
CVE-2011-4310 HIGH
CMS Made Simple < 1.9.4.3 - News Module Article Corruption via Improper Input Validation
Nov 26, 2019
CVSS 7.5
EPSS 0.00
CVE-2011-3718
CMS Made Simple 1.9.2 - Exposure of Sensitive Information via Direct PHP File Request
Sep 23, 2011
EPSS 0.00
CVE-2010-4663
CMS Made Simple < 1.9.1 - Unspecified Vulnerability in News Module
Jun 08, 2011
EPSS 0.00
CVE-2010-3884
CMS Made Simple < 1.8.1 - Cross-Site Request Forgery to Reset Admin Password
Oct 08, 2010
EPSS 0.00
CVE-2010-3883
CMS Made Simple < 1.7.1 - Cross-Site Request Forgery in Change Group Permissions Module
Oct 08, 2010
EPSS 0.00
CVE-2010-3882
CMS Made Simple <= 1.7.1 - Cross-Site Scripting via Multiple Input Modules
Oct 08, 2010
EPSS 0.00
CVE-2010-2797
CMS Made Simple <1.8.1 - Path Traversal
Oct 08, 2010
EPSS 0.00
CVE-2010-1482
CMS Made Simple < 1.7.1 - Cross-Site Scripting via date_format_string Parameter
May 12, 2010
EPSS 0.00
CVE-2008-5642
CMS Made Simple 1.4.1 - Path Traversal
Dec 17, 2008
EPSS 0.10
CVE-2007-6656
CMS Made Simple <1.2.2 - SQL Injection
Jan 04, 2008
EPSS 0.01
CVE-2007-5441
CMS Made Simple 1.1.3.1 - Authenticated Privilege Escalation via Direct Request
Oct 14, 2007
EPSS 0.00
CVE-2007-5442
CMS Made Simple 1.1.3.1 - Authenticated Arbitrary File Upload
Oct 14, 2007
EPSS 0.00
CVE-2007-5443
CMS Made Simple 1.1.3.1 - Cross-Site Scripting via Anchor Tag and Listtags
Oct 14, 2007
EPSS 0.00
CVE-2007-5444
CMS Made Simple 1.1.3.1 - Unauthenticated Path Disclosure via Direct File Request
Oct 14, 2007
EPSS 0.00
CVE-2007-5056
ADOdb Lite < 1.42 - Remote Code Execution via last_module Parameter
Sep 24, 2007
EPSS 0.82