Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cmsmadesimple cms made simple vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2018-10082
CMS Made Simple (CMSMS) up to and including 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or /lib/tas...
Cmsmadesimple Cms Made Simple
9.8
CVSSv3
CVE-2018-10085
CMS Made Simple (CMSMS) up to and including 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\class.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or delete files.
Cmsmadesimple Cms Made Simple
7.2
CVSSv3
CVE-2021-28998
File upload vulnerability in CMS Made Simple up to and including 2.2.15 allows remote authenticated malicious users to gain a webshell via a crafted phar file.
Cmsmadesimple Cms Made Simple
8.8
CVSSv3
CVE-2021-28999
SQL Injection vulnerability in CMS Made Simple up to and including 2.2.15 allows remote malicious users to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
Cmsmadesimple Cms Made Simple
9.8
CVSSv3
CVE-2017-6070
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote malicious users to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.
Cmsmadesimple Form Builder
Cmsmadesimple Cms Made Simple
5.3
CVSSv3
CVE-2017-6071
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote malicious users to conduct information-disclosure attacks via exportxml.
Cmsmadesimple Form Builder
Cmsmadesimple Cms Made Simple
5.3
CVSSv3
CVE-2017-6072
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote malicious users to conduct information-disclosure attacks via defaultadmin.
Cmsmadesimple Form Builder
Cmsmadesimple Cms Made Simple
6.1
CVSSv3
CVE-2023-43339
Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local malicious user to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.
Cmsmadesimple Cms Made Simple 2.2.18
7.8
CVSSv3
CVE-2023-43352
An issue in CMSmadesimple v.2.2.18 allows a local malicious user to execute arbitrary code via a crafted payload to the Content Manager Menu component.
Cmsmadesimple Cms Made Simple 2.2.18
5.4
CVSSv3
CVE-2023-43353
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local malicious user to execute arbitrary code via a crafted script to the extra parameter in the news menu component.
Cmsmadesimple Cms Made Simple 2.2.18
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »