Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cms Made Simple MEDIUM 6.1
CVE-2018-20464

There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a …

No fix yet
Fix from $1,600 2018-12-25
Cms Made Simple MEDIUM 6.1
CVE-2018-18270

XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.

No fix yet
Fix from $1,600 2018-10-12
Cms Made Simple MEDIUM 6.1
CVE-2018-18271

XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.

No fix yet
Fix from $1,600 2018-10-12
Cms Made Simple HIGH 8.8
CVE-2018-10519

CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value withi…

No fix yet
Fix from $1,950 2018-04-27
Cms Made Simple HIGH 7.2
CVE-2018-10515

In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitab…

Fix: after 2.2.7
Fix from $1,950 2018-04-27
Cms Made Simple HIGH 7.2
CVE-2018-10517EPSS 12%

In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploi…

Fix: after 2.2.7
Fix from $1,950 2018-04-27
Cms Made Simple MEDIUM 6.5
CVE-2018-10516

In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerabilit…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Cms Made Simple MEDIUM 6.5
CVE-2018-10518

In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that c…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Cms Made Simple MEDIUM 6.5
CVE-2018-10520

In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Cms Made Simple MEDIUM 5.3
CVE-2018-10523

CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modul…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Cms Made Simple MEDIUM 5.3
CVE-2018-9921

In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site inst…

Mitigation only
Fix from $1,600 2018-04-23
Cms Made Simple HIGH 8.8
CVE-2018-1000158

cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['adm…

No fix yet
Fix from $1,950 2018-04-18
Cms Made Simple CRITICAL 9.8
CVE-2018-10081

CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by …

Fix: after 2.2.7
Fix from $2,300 2018-04-13
Cms Made Simple CRITICAL 9.8
CVE-2018-10085

CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\c…

Fix: after 2.2.6
Fix from $2,300 2018-04-13
Cms Made Simple HIGH 8.8
CVE-2018-10084

CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid val…

Fix: after 2.2.6
Fix from $1,950 2018-04-13
Cms Made Simple HIGH 7.5
CVE-2018-10083

CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in t…

Fix: after 2.2.7
Fix from $1,950 2018-04-13
Cms Made Simple HIGH 7.2
CVE-2018-10086

CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval…

Fix: after 2.2.7
Fix from $1,950 2018-04-13
Cms Made Simple MEDIUM 5.3
CVE-2018-10082

CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact…

Fix: after 2.2.7
Fix from $1,600 2018-04-13
Cms Made Simple HIGH 8.8
CVE-2018-10030

CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.

Fix: after 2.2.7
Fix from $1,950 2018-04-11
Cms Made Simple HIGH 8.8
CVE-2018-10031

CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.

Fix: after 2.2.7
Fix from $1,950 2018-04-11
Cms Made Simple HIGH 8.8
CVE-2018-1000092

CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can…

No fix yet
Fix from $1,950 2018-03-13
Cms Made Simple HIGH 7.2
CVE-2018-1000094EPSS 39%

CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that ha…

No fix yet
Fix from $1,950 2018-03-13
Cms Made Simple HIGH 7.5
CVE-2018-7448EPSS 13%

Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrar…

No fix yet
Fix from $1,950 2018-02-26
Cms Made Simple CRITICAL 9.8
CVE-2017-1000453

CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execu…

Fix: 2.2+
Fix from $2,300 2018-01-02
Cms Made Simple HIGH 7.8
CVE-2017-1000454

CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and l…

Fix: 2.2+
Fix from $1,950 2018-01-02
Cms Made Simple CRITICAL 9.8
CVE-2017-17734

CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.

Fix: 2.2.5+
Fix from $2,300 2017-12-18
Cms Made Simple CRITICAL 9.8
CVE-2017-17735

CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.

Fix: 2.2.5+
Fix from $2,300 2017-12-18
Cms Made Simple MEDIUM 5.4
CVE-2017-16798

In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end wi…

Mitigation only
Fix from $1,600 2017-11-12
Cmsmadesimple MEDIUM 5.4
CVE-2017-16799

In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php duri…

Mitigation only
Fix from $1,600 2017-11-12
Cms Made Simple CRITICAL 9.8
CVE-2017-16783EPSS 8%

In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.

No fix yet
Fix from $2,300 2017-11-10