VYPR

FileManager

by Cmsmadesimple

CVEs (5)

  • CVE-2020-10682HigMar 20, 2020
    risk 0.51cvss 7.8epss 0.02

    The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).

  • CVE-2025-63678HigNov 10, 2025
    risk 0.47cvss 7.2epss 0.00

    An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2020-10681MedMar 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.

  • CVE-2019-11513MedApr 25, 2019
    risk 0.31cvss 4.8epss 0.01

    The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.

  • CVE-2008-2267May 16, 2008
    risk 0.03cvss —epss 0.05

    Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6)…