Show filters
67 Total Results
Displaying 31-40 of 67
Sort by:
Attacker Value
Unknown
CVE-2020-36412
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.
0
Attacker Value
Unknown
CVE-2020-27377
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
0
Attacker Value
Unknown
CVE-2021-28935
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.
0
Attacker Value
Unknown
CVE-2020-20138
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
0
Attacker Value
Unknown
CVE-2020-24860
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
0
Attacker Value
Unknown
CVE-2020-17462
Disclosure Date: August 14, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
0
Attacker Value
Unknown
CVE-2020-14926
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
0
Attacker Value
Unknown
CVE-2020-10682
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).
0
Attacker Value
Unknown
CVE-2020-10681
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.
0
Attacker Value
Unknown
CVE-2019-17629
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
0