Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown

CVE-2023-43872

Disclosure Date: September 28, 2023 (last updated October 31, 2023)
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2023-43339

Disclosure Date: September 25, 2023 (last updated November 08, 2023)
Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.
Attacker Value
Unknown

CVE-2023-36970

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
Attacker Value
Unknown

CVE-2023-36969

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Attacker Value
Unknown

CVE-2021-43154

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
Attacker Value
Unknown

CVE-2022-23907

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
Attacker Value
Unknown

CVE-2022-23906

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
Attacker Value
Unknown

CVE-2020-23481

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
Attacker Value
Unknown

CVE-2019-9060

Disclosure Date: September 17, 2021 (last updated February 23, 2025)
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).
Attacker Value
Unknown

CVE-2020-22732

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..