Show filters
150 Total Results
Displaying 1-10 of 150
Sort by:
Attacker Value
Moderate

CVE-2019-9053

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
3
Attacker Value
Unknown

CVE-2024-1529

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially take over their browser session.
0
Attacker Value
Unknown

CVE-2024-1528

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
0
Attacker Value
Unknown

CVE-2024-1527

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.
0
Attacker Value
Unknown

CVE-2023-43352

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
Attacker Value
Unknown

CVE-2023-43360

Disclosure Date: October 25, 2023 (last updated October 31, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.
Attacker Value
Unknown

CVE-2023-43358

Disclosure Date: October 23, 2023 (last updated October 30, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.
Attacker Value
Unknown

CVE-2023-43357

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.
Attacker Value
Unknown

CVE-2023-43356

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.
Attacker Value
Unknown

CVE-2023-43355

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.