Vulnerability index

Browse CVEs

74 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-36413 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36414 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36415 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2021-28935 CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. Cms Made Simple No fix yet Fix from $1,6002021-03-30 MEDIUM 6.1 CVE-2020-20138 Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4. Cms Made Simple No fix yet Fix from $1,6002020-12-17 MEDIUM 5.4 CVE-2020-24860 CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected… Cms Made Simple No fix yet Fix from $1,6002020-10-01 HIGH 7.8 CVE-2020-17462 CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16… Cms Made Simple No fix yet Fix from $1,9502020-08-14 MEDIUM 5.4 CVE-2020-14926 CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page. Cms Made Simple No fix yet Fix from $1,6002020-06-19 HIGH 7.8 CVE-2020-10682 The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinter… Cms Made Simple No fix yet Fix from $1,9502020-03-20 MEDIUM 5.4 CVE-2020-10681 The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php. Cms Made Simple No fix yet Fix from $1,6002020-03-20 MEDIUM 5.4 CVE-2019-11226 CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News. Cms Made Simple No fix yet Fix from $1,6002019-06-05 HIGH 8.8 CVE-2019-9056 An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersMa… Cms Made Simple Mitigation only Fix from $1,9502019-04-11 MEDIUM 5.4 CVE-2019-10105 CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" acti… Cms Made Simple No fix yet Fix from $1,6002019-03-26 MEDIUM 5.4 CVE-2019-10106 CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings … Cms Made Simple No fix yet Fix from $1,6002019-03-26 MEDIUM 5.4 CVE-2019-10107 CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section. Cms Made Simple No fix yet Fix from $1,6002019-03-26 HIGH 8.1 CVE-2019-9053EPSS 69% An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-b… Cms Made Simple No fix yet Fix from $1,9502019-03-26 MEDIUM 5.4 CVE-2019-10017 CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker. Cms Made Simple No fix yet Fix from $1,6002019-03-24 MEDIUM 6.1 CVE-2018-20464 There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a … Cms Made Simple No fix yet Fix from $1,6002018-12-25 MEDIUM 6.1 CVE-2018-18270 XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action. Cms Made Simple No fix yet Fix from $1,6002018-10-12 MEDIUM 6.1 CVE-2018-18271 XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action. Cms Made Simple No fix yet Fix from $1,6002018-10-12 HIGH 8.8 CVE-2018-10519 CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value withi… Cms Made Simple No fix yet Fix from $1,9502018-04-27 MEDIUM 5.3 CVE-2018-9921 In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site inst… Cms Made Simple Mitigation only Fix from $1,6002018-04-23 HIGH 8.8 CVE-2018-1000158 cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['adm… Cms Made Simple No fix yet Fix from $1,9502018-04-18 HIGH 8.8 CVE-2018-1000092 CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can… Cms Made Simple No fix yet Fix from $1,9502018-03-13 HIGH 7.2 CVE-2018-1000094EPSS 39% CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that ha… Cms Made Simple No fix yet Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-7448EPSS 13% Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrar… Cms Made Simple No fix yet Fix from $1,9502018-02-26 MEDIUM 5.4 CVE-2017-16798 In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end wi… Cms Made Simple Mitigation only Fix from $1,6002017-11-12 MEDIUM 5.4 CVE-2017-16799 In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php duri… Cmsmadesimple Mitigation only Fix from $1,6002017-11-12 CRITICAL 9.8 CVE-2017-16783EPSS 8% In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. Cms Made Simple No fix yet Fix from $2,3002017-11-10 MEDIUM 6.1 CVE-2017-16784 In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter. Cms Made Simple No fix yet Fix from $1,6002017-11-10