Medium severity5.9NVD Advisory· Published Mar 5, 2024· Updated Jun 17, 2026
CVE-2024-27623
CVE-2024-27623
Description
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.19:*:*:*:*:*:*:*
- CMS Made Simple/CMS Made Simpledescription
- Range: = 2.2.19
Patches
Vulnerability mechanics
References
1- www.vicarius.io/vsociety/posts/pwning-cmsms-via-user-defined-tags-for-fun-and-learning-cve-2024-27622-27623nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.