Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-16784 In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter. Cms Made Simple No fix yet Fix from $1,6002017-11-10 MEDIUM 6.1 CVE-2017-9668 In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via th… Cms Made Simple Mitigation only Fix from $1,6002017-06-18 HIGH 7.2 CVE-2017-8912 CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.ph… Cms Made Simple Patch available Fix from $1,9502017-05-12 MEDIUM 5.4 CVE-2017-7255 XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the … Cms Made Simple No fix yet Fix from $1,6002017-03-24 MEDIUM 5.4 CVE-2017-7256 XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct th… Cms Made Simple No fix yet Fix from $1,6002017-03-24 MEDIUM 5.4 CVE-2017-7257 XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct th… Cms Made Simple No fix yet Fix from $1,6002017-03-24 MEDIUM 5.4 CVE-2017-6555 Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary… Cms Made Simple No fix yet Fix from $1,6002017-03-09 MEDIUM 5.4 CVE-2017-6556 Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML vi… Cms Made Simple No fix yet Fix from $1,6002017-03-09 CRITICAL 9.8 CVE-2017-6070 CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template p… Form Builder after 1.12.2 Fix from $2,3002017-02-21 MEDIUM 5.3 CVE-2017-6071 CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml. Form Builder after 1.12.2 Fix from $1,6002017-02-21 MEDIUM 5.3 CVE-2017-6072 CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin. Form Builder after 1.12.2 Fix from $1,6002017-02-21 HIGH 8.0 CVE-2016-7904 Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrator… Cms Made Simple after 2.1.5 Fix from $1,9502017-01-16 MEDIUM 6.0 CVE-2014-2245 SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" per… Cms Made Simple after 1.11.9 Fix from $1,6002014-03-05 MEDIUM 6.8 CVE-2012-5450 Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remot… Cms Made Simple after 1.11.2 Fix from $1,6002012-12-03 MEDIUM 5.0 CVE-2011-3718 CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installa… Cms Made Simple No fix yet Fix from $1,6002011-09-23 HIGH 10.0 CVE-2010-4663 Unspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack vectors. Cms Made Simple after 1.9 Fix from $1,9502011-06-08 MEDIUM 6.8 CVE-2010-3883 Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers t… Cms Made Simple after 1.7.1 Fix from $1,6002010-10-08 MEDIUM 6.8 CVE-2010-3884 Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administ… Cms Made Simple after 1.8.1 Fix from $1,6002010-10-08 HIGH 7.5 CVE-2010-2797EPSS 8% Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arb… Cms Made Simple after 1.6.8 Fix from $1,9502010-10-08 MEDIUM 5.0 CVE-2008-5642EPSS 9% Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a… Cms Made Simple No fix yet Fix from $1,6002008-12-17 HIGH 7.5 CVE-2007-6656 SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitra… Cms Made Simple after 1.2.2 Fix from $1,9502008-01-04 MEDIUM 6.5 CVE-2007-5441 CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some … Cms Made Simple Mitigation only Fix from $1,6002007-10-14 MEDIUM 5.0 CVE-2007-5444 CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files. Cms Made Simple No fix yet Fix from $1,6002007-10-14 HIGH 7.5 CVE-2007-2473 SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the … Cms Made Simple after 1.0.5 Fix from $1,9502007-05-02 MEDIUM 6.8 CVE-2007-0610 Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML … Cms Made Simple Mitigation only Fix from $1,6002007-01-31 HIGH 7.5 CVE-2007-0551 Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL… Cms Made Simple Mitigation only Fix from $1,9502007-01-29 MEDIUM 6.8 CVE-2006-6844 Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web… Cms Made Simple No fix yet Fix from $1,6002006-12-31 MEDIUM 6.8 CVE-2006-6845 Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the… Cms Made Simple Mitigation only Fix from $1,6002006-12-31 HIGH 7.5 CVE-2005-2846EPSS 7% PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the… Cms Made Simple Patch available Fix from $1,9502005-09-08