Cmsmadesimple / Cms Made Simple
155 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-37238 | CMS Made Simple 2.2.15 Stored XSS via SVG File Upload | MEDIUM | 5.1 | May 16, 2026 |
| CVE-2026-5203 | CMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversal | MEDIUM | 5.1 | Mar 31, 2026 |
| CVE-2026-4225 | CMS Made Simple User Management listusers.php cross site scripting | MEDIUM | 4.8 | Mar 16, 2026 |
| CVE-2025-5153 | CMS Made Simple Design Manager Module cross site scripting | MEDIUM | 5.1 | May 25, 2025 |
| CVE-2024-1529 | Cross-site Scripting in CMS Made Simple | HIGH | 7.4 | Mar 12, 2024 |
| CVE-2024-1528 | Cross-site Scripting in CMS Made Simple | HIGH | 7.4 | Mar 12, 2024 |
| CVE-2024-1527 | Unrestricted Upload of File with Dangerous Type in CMS Made Simple | CRITICAL | 9.8 | Mar 12, 2024 |
| CVE-2024-27625 | CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifica… | MEDIUM | 4.8 | Mar 5, 2024 |
| CVE-2024-27623 | CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when ed… | MEDIUM | 5.9 | Mar 5, 2024 |
| CVE-2024-27622 | A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises… | HIGH | 7.2 | Mar 5, 2024 |
| CVE-2023-43352 | An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component. | HIGH | 7.8 | Oct 26, 2023 |
| CVE-2023-43360 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parame… | MEDIUM | 5.4 | Oct 24, 2023 |
| CVE-2023-43358 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in t… | MEDIUM | 5.4 | Oct 23, 2023 |
| CVE-2023-43357 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in t… | MEDIUM | 5.4 | Oct 20, 2023 |
| CVE-2023-43356 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata par… | MEDIUM | 5.4 | Oct 20, 2023 |
| CVE-2023-43355 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and passwor… | MEDIUM | 5.4 | Oct 20, 2023 |
| CVE-2023-43354 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter i… | MEDIUM | 5.4 | Oct 20, 2023 |
| CVE-2023-43353 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in t… | MEDIUM | 5.4 | Oct 20, 2023 |
| CVE-2023-43359 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metada… | MEDIUM | 5.4 | Oct 19, 2023 |
| CVE-2023-43872 | A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). | MEDIUM | 5.4 | Sep 28, 2023 |
| CVE-2023-43339 | Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Da… | MEDIUM | 6.1 | Sep 25, 2023 |
| CVE-2023-36970 | A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload functi… | MEDIUM | 5.4 | Jul 6, 2023 |
| CVE-2023-36969 | CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | HIGH | 8.8 | Jul 6, 2023 |
| CVE-2021-28999 | SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News… | HIGH | 8.8 | May 8, 2023 |
| CVE-2021-28998 | File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file. | HIGH | 7.2 | May 8, 2023 |
Showing 1 to 25 of 155 CVEs