Show filters
150 Total Results
Displaying 21-30 of 150
Sort by:
Attacker Value
Unknown

CVE-2021-43154

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
Attacker Value
Unknown

CVE-2022-23907

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
Attacker Value
Unknown

CVE-2022-23906

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
Attacker Value
Unknown

CVE-2020-23481

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
Attacker Value
Unknown

CVE-2019-9060

Disclosure Date: September 17, 2021 (last updated February 23, 2025)
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).
Attacker Value
Unknown

CVE-2020-22732

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
Attacker Value
Unknown

CVE-2020-23241

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
Attacker Value
Unknown

CVE-2020-23240

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
Attacker Value
Unknown

CVE-2020-36416

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.
Attacker Value
Unknown

CVE-2020-36410

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter under the "Options" module.