Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-36410 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36411 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36412 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36413 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36414 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36415 A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a … Cms Made Simple No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2021-28935 CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. Cms Made Simple No fix yet Fix from $1,6002021-03-30 MEDIUM 6.1 CVE-2020-20138 Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4. Cms Made Simple No fix yet Fix from $1,6002020-12-17 MEDIUM 5.4 CVE-2020-24860 CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected… Cms Made Simple No fix yet Fix from $1,6002020-10-01 MEDIUM 5.4 CVE-2020-22842 CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php. Cms Made Simple 2.2.15+ Fix from $1,6002020-09-30 HIGH 7.8 CVE-2020-17462 CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16… Cms Made Simple No fix yet Fix from $1,9502020-08-14 MEDIUM 5.4 CVE-2020-14926 CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page. Cms Made Simple No fix yet Fix from $1,6002020-06-19 HIGH 7.8 CVE-2020-10682 The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinter… Cms Made Simple No fix yet Fix from $1,9502020-03-20 MEDIUM 5.4 CVE-2020-10681 The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php. Cms Made Simple No fix yet Fix from $1,6002020-03-20 HIGH 7.5 CVE-2011-4310 The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles. Cms Made Simple 1.9.4.3+ Fix from $1,9502019-11-26 MEDIUM 6.1 CVE-2019-1010290 Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "n… Bable\ after 0.4.1 Fix from $1,6002019-07-16 MEDIUM 5.4 CVE-2019-11226 CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News. Cms Made Simple No fix yet Fix from $1,6002019-06-05 HIGH 8.8 CVE-2019-9056 An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersMa… Cms Made Simple Mitigation only Fix from $1,9502019-04-11 MEDIUM 5.4 CVE-2019-10105 CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" acti… Cms Made Simple No fix yet Fix from $1,6002019-03-26 MEDIUM 5.4 CVE-2019-10106 CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings … Cms Made Simple No fix yet Fix from $1,6002019-03-26 MEDIUM 5.4 CVE-2019-10107 CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section. Cms Made Simple No fix yet Fix from $1,6002019-03-26 HIGH 8.8 CVE-2019-9055EPSS 12% An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.… Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 8.8 CVE-2019-9057 An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, … Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 8.8 CVE-2019-9061 An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unse… Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 8.1 CVE-2019-9053EPSS 69% An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-b… Cms Made Simple No fix yet Fix from $1,9502019-03-26 HIGH 7.2 CVE-2019-9058 An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the … Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 7.2 CVE-2019-9059 An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path o… Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 MEDIUM 5.4 CVE-2019-10017 CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker. Cms Made Simple No fix yet Fix from $1,6002019-03-24 HIGH 8.8 CVE-2019-9693 In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (… Cms Made Simple 2.2.10+ Fix from $1,9502019-03-11 MEDIUM 6.5 CVE-2019-9692EPSS 46% class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JP… Cms Made Simple 2.2.10+ Fix from $1,6002019-03-11