Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2021-47735 CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template… Cmsimple No fix yet Fix from $1,9502025-12-23 HIGH 7.8 CVE-2021-47734 CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute ar… Cmsimple No fix yet Fix from $1,9502025-12-23 MEDIUM 6.1 CVE-2021-47732 CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious J… Cmsimple No fix yet Fix from $1,6002025-12-23 MEDIUM 6.1 CVE-2021-47733 CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attacke… Cmsimple No fix yet Fix from $1,6002025-12-23 HIGH 8.8 CVE-2024-58280 CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PH… Cmsimple No fix yet Fix from $1,9502025-12-10 CRITICAL 9.1 CVE-2024-57548 CMSimple 5.16 allows the user to edit log.php file via print page. Cmsimple No fix yet Fix from $2,3002025-01-27 HIGH 7.5 CVE-2024-57547 Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functional… Cmsimple No fix yet Fix from $1,9502025-01-27 HIGH 7.5 CVE-2024-57549 CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request. Cmsimple No fix yet Fix from $1,9502025-01-27 HIGH 7.5 CVE-2024-57546 An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function. Cmsimple No fix yet Fix from $1,9502025-01-27 HIGH 7.4 CVE-2024-33423 Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a craft… Cmsimple No fix yet Fix from $1,9502024-05-01 MEDIUM 6.1 CVE-2024-33424 A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a cra… Cmsimple No fix yet Fix from $1,6002024-05-01 HIGH 7.2 CVE-2024-32345 A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a cra… Cmsimple No fix yet Fix from $1,9502024-04-17 MEDIUM 6.8 CVE-2024-32344 A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a cra… Cmsimple No fix yet Fix from $1,6002024-04-17 CRITICAL 9.8 CVE-2021-43741 CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading… Cmsimple No fix yet Fix from $2,3002022-04-13 MEDIUM 5.4 CVE-2021-43742 CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature. Cmsimple No fix yet Fix from $1,6002022-04-13 MEDIUM 6.8 CVE-2008-2650EPSS 19% Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execu… Cmsimple No fix yet Fix from $1,6002008-06-10