Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-63678 An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers wi… File Manager No fix yet Fix from $1,9502025-11-10 MEDIUM 6.1 CVE-2024-1528 CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /… Cms Made Simple Mitigation only Fix from $1,6002024-03-12 MEDIUM 6.1 CVE-2024-1529 Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerab… Cms Made Simple Mitigation only Fix from $1,6002024-03-12 HIGH 8.8 CVE-2024-1527 Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the se… Cms Made Simple Mitigation only Fix from $1,9502024-03-12 HIGH 7.2 CVE-2024-27622 A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerabil… Cms Made Simple No fix yet Fix from $1,9502024-03-05 MEDIUM 5.9 CVE-2024-27623 CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particular… Cms Made Simple No fix yet Fix from $1,6002024-03-05 HIGH 7.8 CVE-2023-43352 An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component. Cms Made Simple No fix yet Fix from $1,9502023-10-26 MEDIUM 5.4 CVE-2023-43360 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Direct… Cms Made Simple No fix yet Fix from $1,6002023-10-25 MEDIUM 5.4 CVE-2023-43358 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title para… Cms Made Simple No fix yet Fix from $1,6002023-10-23 MEDIUM 5.4 CVE-2023-43353 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra para… Cms Made Simple No fix yet Fix from $1,6002023-10-20 MEDIUM 5.4 CVE-2023-43354 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles p… Cms Made Simple No fix yet Fix from $1,6002023-10-20 MEDIUM 5.4 CVE-2023-43355 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password a… Cms Made Simple No fix yet Fix from $1,6002023-10-20 MEDIUM 5.4 CVE-2023-43356 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Mea… Cms Made Simple No fix yet Fix from $1,6002023-10-20 MEDIUM 5.4 CVE-2023-43357 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title para… Cms Made Simple No fix yet Fix from $1,6002023-10-20 MEDIUM 5.4 CVE-2023-43359 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Speci… Cms Made Simple No fix yet Fix from $1,6002023-10-19 MEDIUM 5.4 CVE-2023-43872 A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). Cms Made Simple No fix yet Fix from $1,6002023-09-28 MEDIUM 6.1 CVE-2023-43339 Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected i… Cms Made Simple No fix yet Fix from $1,6002023-09-25 MEDIUM 5.4 CVE-2023-36970 A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upl… Cms Made Simple No fix yet Fix from $1,6002023-07-06 HIGH 8.8 CVE-2023-36969EPSS 49% CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. Cms Made Simple No fix yet Fix from $1,9502023-07-06 HIGH 8.8 CVE-2021-28999 SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to mo… Cms Made Simple after 2.2.15 Fix from $1,9502023-05-08 HIGH 7.2 CVE-2021-28998 File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file. Cms Made Simple after 2.2.15 Fix from $1,9502023-05-08 HIGH 8.8 CVE-2021-40961 CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $quer… Cms Made Simple after 2.2.15 Fix from $1,9502022-06-09 MEDIUM 6.1 CVE-2021-43154 Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php. Cms Made Simple Mitigation only Fix from $1,6002022-04-13 HIGH 7.2 CVE-2022-23906 CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability i… Cms Made Simple No fix yet Fix from $1,9502022-02-28 MEDIUM 6.1 CVE-2022-23907 CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage. Cms Made Simple No fix yet Fix from $1,6002022-02-28 MEDIUM 5.4 CVE-2020-23481 CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts o… Cms Made Simple No fix yet Fix from $1,6002021-09-22 HIGH 7.5 CVE-2019-9060 An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file ac… Cms Made Simple Mitigation only Fix from $1,9502021-09-17 MEDIUM 5.4 CVE-2020-36416 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36408 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36409 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02