Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cmsmadesimple cms made simple vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2017-17734
CMS Made Simple (CMSMS) prior to 2.2.5 does not properly cache login information in sessions.
Cmsmadesimple Cms Made Simple
5
CVSSv2
CVE-2017-17735
CMS Made Simple (CMSMS) prior to 2.2.5 does not properly cache login information in cookies.
Cmsmadesimple Cms Made Simple
6.5
CVSSv2
CVE-2018-10084
CMS Made Simple (CMSMS) up to and including 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection mechanism can be bypassed...
Cmsmadesimple Cms Made Simple
6.5
CVSSv2
CVE-2018-10086
CMS Made Simple (CMSMS) up to and including 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "t...
Cmsmadesimple Cms Made Simple
7.5
CVSSv2
CVE-2017-6070
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote malicious users to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.
Cmsmadesimple Form Builder
Cmsmadesimple Cms Made Simple
5
CVSSv2
CVE-2017-6071
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote malicious users to conduct information-disclosure attacks via exportxml.
Cmsmadesimple Form Builder
Cmsmadesimple Cms Made Simple
5
CVSSv2
CVE-2017-6072
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote malicious users to conduct information-disclosure attacks via defaultadmin.
Cmsmadesimple Form Builder
Cmsmadesimple Cms Made Simple
3.5
CVSSv2
CVE-2018-5965
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
Cmsmadesimple Cms Made Simple 2.2.5
6.5
CVSSv2
CVE-2022-23906
CMS Made Simple v2.2.15 exists to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
Cmsmadesimple Cms Made Simple 2.2.15
4.3
CVSSv2
CVE-2022-23907
CMS Made Simple v2.2.15 exists to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
Cmsmadesimple Cms Made Simple 2.2.15
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »