Show filters
150 Total Results
Displaying 11-20 of 150
Sort by:
Attacker Value
Unknown

CVE-2023-43354

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.
Attacker Value
Unknown

CVE-2023-43353

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.
Attacker Value
Unknown

CVE-2023-43359

Disclosure Date: October 19, 2023 (last updated October 31, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.
Attacker Value
Unknown

CVE-2023-43872

Disclosure Date: September 28, 2023 (last updated October 31, 2023)
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2023-43339

Disclosure Date: September 25, 2023 (last updated November 08, 2023)
Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.
Attacker Value
Unknown

CVE-2023-36970

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
Attacker Value
Unknown

CVE-2023-36969

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Attacker Value
Unknown

CVE-2021-28999

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
Attacker Value
Unknown

CVE-2021-28998

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
Attacker Value
Unknown

CVE-2021-40961

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.