Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cmsimple HIGH 8.8
CVE-2021-47735

CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template…

No fix yet
Fix from $1,950 2025-12-23
Cmsimple HIGH 7.8
CVE-2021-47734

CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute ar…

No fix yet
Fix from $1,950 2025-12-23
Cmsimple MEDIUM 6.1
CVE-2021-47732

CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious J…

No fix yet
Fix from $1,600 2025-12-23
Cmsimple MEDIUM 6.1
CVE-2021-47733

CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attacke…

No fix yet
Fix from $1,600 2025-12-23
Cmsimple HIGH 8.8
CVE-2024-58280

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PH…

No fix yet
Fix from $1,950 2025-12-10
Cmsimple CRITICAL 9.1
CVE-2024-57548

CMSimple 5.16 allows the user to edit log.php file via print page.

No fix yet
Fix from $2,300 2025-01-27
Cmsimple HIGH 7.5
CVE-2024-57547

Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functional…

No fix yet
Fix from $1,950 2025-01-27
Cmsimple HIGH 7.5
CVE-2024-57549

CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.

No fix yet
Fix from $1,950 2025-01-27
Cmsimple HIGH 7.5
CVE-2024-57546

An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.

No fix yet
Fix from $1,950 2025-01-27
Cmsimple HIGH 7.4
CVE-2024-33423

Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a craft…

No fix yet
Fix from $1,950 2024-05-01
Cmsimple MEDIUM 6.1
CVE-2024-33424

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a cra…

No fix yet
Fix from $1,600 2024-05-01
Cmsimple HIGH 7.2
CVE-2024-32345

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a cra…

No fix yet
Fix from $1,950 2024-04-17
Cmsimple MEDIUM 6.8
CVE-2024-32344

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a cra…

No fix yet
Fix from $1,600 2024-04-17
Cmsimple CRITICAL 9.8
CVE-2021-43741

CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading…

No fix yet
Fix from $2,300 2022-04-13
Cmsimple MEDIUM 5.4
CVE-2021-43742

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

No fix yet
Fix from $1,600 2022-04-13
Cmsimple MEDIUM 6.8
CVE-2008-2650EPSS 19%

Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execu…

No fix yet
Fix from $1,600 2008-06-10