Get-Simple / Getsimple Cms
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-41544 | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. | CRITICAL | 9.8 | Oct 18, 2022 |
| CVE-2022-1503 | GetSimple CMS Content Module edit.php cross site scripting | MEDIUM | 5.4 | Apr 27, 2022 |
| CVE-2020-24861 | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page | MEDIUM | 5.4 | Oct 1, 2020 |
| CVE-2020-23839 | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute… | MEDIUM | 6.1 | Sep 1, 2020 |
| CVE-2013-1420 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id… | MEDIUM | 6.1 | Jan 2, 2020 |
| CVE-2019-16333 | GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php. | MEDIUM | 5.4 | Sep 15, 2019 |
| CVE-2019-11231 | An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content… | CRITICAL | 9.8 | May 22, 2019 |
| CVE-2018-19845 | There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325. | MEDIUM | 5.4 | Dec 31, 2018 |
| CVE-2018-19421 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php,… | LOW | 3.8 | Nov 21, 2018 |
| CVE-2018-19420 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no ext… | LOW | 3.8 | Nov 21, 2018 |
| CVE-2018-17835 | An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which… | MEDIUM | 4.8 | Oct 1, 2018 |
| CVE-2018-17103 | An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The… | HIGH | 8.8 | Sep 16, 2018 |
| CVE-2018-16325 | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field. | MEDIUM | 6.1 | Sep 1, 2018 |
| CVE-2018-15843 | GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field. | MEDIUM | 4.8 | Aug 25, 2018 |
| CVE-2018-9173 | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web s… | MEDIUM | 6.1 | Apr 2, 2018 |
| CVE-2017-10673 | admin/profile.php in GetSimple CMS 3.x has XSS in a name field. | MEDIUM | 6.1 | Jun 29, 2017 |
| CVE-2014-8723 | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlu… | MEDIUM | 5.3 | Mar 17, 2017 |
| CVE-2014-8722 | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>… | HIGH | 7.5 | Mar 17, 2017 |
| CVE-2015-5356 | Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | Jul 1, 2015 |
| CVE-2015-5355 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) pos… | MEDIUM | 4.3 | Jul 1, 2015 |
| CVE-2014-8790 | XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remot… | MEDIUM | 5.0 | Jan 20, 2015 |
| CVE-2014-1603 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param para… | MEDIUM | 4.3 | May 14, 2014 |
| CVE-2013-7243 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1.2 and 3.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1)… | MEDIUM | 4.3 | Jan 17, 2014 |
| CVE-2012-6621 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inject arbitrary web script or HT… | MEDIUM | 4.3 | Jan 16, 2014 |
| CVE-2010-5052 | Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the v… | MEDIUM | 4.3 | Nov 23, 2011 |
Showing 1 to 25 of 26 CVEs