Medium severity5.4NVD Advisory· Published Jul 6, 2023· Updated Jun 17, 2026
CVE-2023-36970
CVE-2023-36970
Description
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.17:*:*:*:*:*:*:*
- CMS Made Simple/CMS Made Simpledescription
- Range: =2.2.17
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.