Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-20464 There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a … Cms Made Simple No fix yet Fix from $1,6002018-12-25 MEDIUM 6.1 CVE-2018-18270 XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action. Cms Made Simple No fix yet Fix from $1,6002018-10-12 MEDIUM 6.1 CVE-2018-18271 XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action. Cms Made Simple No fix yet Fix from $1,6002018-10-12 HIGH 8.8 CVE-2018-10519 CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value withi… Cms Made Simple No fix yet Fix from $1,9502018-04-27 HIGH 7.2 CVE-2018-10515 In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitab… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-27 HIGH 7.2 CVE-2018-10517EPSS 12% In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploi… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-27 MEDIUM 6.5 CVE-2018-10516 In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerabilit… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-27 MEDIUM 6.5 CVE-2018-10518 In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that c… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-27 MEDIUM 6.5 CVE-2018-10520 In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-27 MEDIUM 5.3 CVE-2018-10523 CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modul… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-27 MEDIUM 5.3 CVE-2018-9921 In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site inst… Cms Made Simple Mitigation only Fix from $1,6002018-04-23 HIGH 8.8 CVE-2018-1000158 cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['adm… Cms Made Simple No fix yet Fix from $1,9502018-04-18 CRITICAL 9.8 CVE-2018-10081 CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by … Cms Made Simple after 2.2.7 Fix from $2,3002018-04-13 CRITICAL 9.8 CVE-2018-10085 CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\c… Cms Made Simple after 2.2.6 Fix from $2,3002018-04-13 HIGH 8.8 CVE-2018-10084 CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid val… Cms Made Simple after 2.2.6 Fix from $1,9502018-04-13 HIGH 7.5 CVE-2018-10083 CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in t… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-13 HIGH 7.2 CVE-2018-10086 CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-13 MEDIUM 5.3 CVE-2018-10082 CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-13 HIGH 8.8 CVE-2018-10030 CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php. Cms Made Simple after 2.2.7 Fix from $1,9502018-04-11 HIGH 8.8 CVE-2018-10031 CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php. Cms Made Simple after 2.2.7 Fix from $1,9502018-04-11 HIGH 8.8 CVE-2018-1000092 CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can… Cms Made Simple No fix yet Fix from $1,9502018-03-13 HIGH 7.2 CVE-2018-1000094EPSS 39% CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that ha… Cms Made Simple No fix yet Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-7448EPSS 13% Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrar… Cms Made Simple No fix yet Fix from $1,9502018-02-26 CRITICAL 9.8 CVE-2017-1000453 CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execu… Cms Made Simple 2.2+ Fix from $2,3002018-01-02 HIGH 7.8 CVE-2017-1000454 CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and l… Cms Made Simple 2.2+ Fix from $1,9502018-01-02 CRITICAL 9.8 CVE-2017-17734 CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions. Cms Made Simple 2.2.5+ Fix from $2,3002017-12-18 CRITICAL 9.8 CVE-2017-17735 CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies. Cms Made Simple 2.2.5+ Fix from $2,3002017-12-18 MEDIUM 5.4 CVE-2017-16798 In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end wi… Cms Made Simple Mitigation only Fix from $1,6002017-11-12 MEDIUM 5.4 CVE-2017-16799 In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php duri… Cmsmadesimple Mitigation only Fix from $1,6002017-11-12 CRITICAL 9.8 CVE-2017-16783EPSS 8% In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. Cms Made Simple No fix yet Fix from $2,3002017-11-10