Skip to main content

Vendor/product archive

cmsmadesimple / cms_made_simple CVEs

Beta · best-effort

154 CVEs tagged to cmsmadesimple / cms_made_simple9 Critical, 41 High, 99 Medium, 5 Low, 0 Unrated.

CVE-2025-5153

Published May 25, 2025

A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design Manager Module.…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1529

Published Mar 12, 2024

Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.p…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1528

Published Mar 12, 2024

CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1527

Published Mar 12, 2024

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27625

Published Mar 5, 2024

CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arise…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27623

Published Mar 5, 2024

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumb…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27622

Published Mar 5, 2024

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate san…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43352

Published Oct 26, 2023

An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43360

Published Oct 25, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Pick…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43358

Published Oct 23, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu compone…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43357

Published Oct 20, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43356

Published Oct 20, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43355

Published Oct 20, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43354

Published Oct 20, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -Mi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43353

Published Oct 20, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu compone…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43359

Published Oct 19, 2023

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data p…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43872

Published Sep 28, 2023

A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43339

Published Sep 25, 2023

Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBas…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36970

Published Jul 6, 2023

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28999

Published May 8, 2023

SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_arti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28998

Published May 8, 2023

File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40961

Published Jun 9, 2022

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inje…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43154

Published Apr 13, 2022

Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23907

Published Feb 28, 2022

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 154 CVEsPage 1 of 7