Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cmsmadesimple vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2019-9058
An issue exists in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.
Cmsmadesimple Cms Made Simple
8.8
CVSSv3
CVE-2021-28999
SQL Injection vulnerability in CMS Made Simple up to and including 2.2.15 allows remote malicious users to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
Cmsmadesimple Cms Made Simple
9.8
CVSSv3
CVE-2017-17734
CMS Made Simple (CMSMS) prior to 2.2.5 does not properly cache login information in sessions.
Cmsmadesimple Cms Made Simple
7.8
CVSSv3
CVE-2017-1000454
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read prior to 2.2, and local file inclusion since 2.2.1
Cmsmadesimple Cms Made Simple
6.1
CVSSv3
CVE-2019-1010290
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacke...
Cmsmadesimple Bable Multilingual Site
6.5
CVSSv3
CVE-2019-9692
class.showtime2_image.php in CMS Made Simple (CMSMS) prior to 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
Cmsmadesimple Cms Made Simple
2 EDB exploits
1 Github repository
4.8
CVSSv3
CVE-2019-11513
The File Manager in CMS Made Simple up to and including 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
Cmsmadesimple Cms Made Simple
8
CVSSv3
CVE-2016-7904
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple prior to 2.1.6 allows remote malicious users to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.
Cmsmadesimple Cms Made Simple
5.4
CVSSv3
CVE-2020-22842
CMS Made Simple prior to 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
Cmsmadesimple Cms Made Simple
NA
CVE-2010-3884
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and previous versions allows remote malicious users to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; th...
Cmsmadesimple Cms Made Simple
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »