Medium severity5.4NVD Advisory· Published Jul 2, 2021· Updated Jun 17, 2026
CVE-2020-36412
CVE-2020-36412
Description
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.14:*:*:*:*:*:*:*
- CMS Made Simple/CMS Made Simpledescription
- Range: <2.2.14
Patches
Vulnerability mechanics
References
1- dev.cmsmadesimple.org/bug/view/12325nvdExploitIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.