Cmsmadesimple
Source repositories
CVEs (156)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10031 | Hig | 0.57 | 8.8 | 0.00 | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php. | ||
| CVE-2018-10030 | Hig | 0.57 | 8.8 | 0.00 | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php. | ||
| CVE-2018-1000092 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2018 | CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page.… | ||
| CVE-2018-1000094 | Hig | 0.53 | 7.2 | 0.39 | Mar 13, 2018 | CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any… | ||
| CVE-2018-7448 | Hig | 0.53 | 7.5 | 0.13 | Feb 26, 2018 | Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure. | ||
| CVE-2016-7904 | Hig | 0.52 | 8.0 | 0.01 | Jan 16, 2017 | Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request. | ||
| CVE-2023-43352 | Hig | 0.51 | 7.8 | 0.01 | Oct 26, 2023 | An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component. | ||
| CVE-2020-17462 | Hig | 0.51 | 7.8 | 0.01 | Aug 14, 2020 | CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798. | ||
| CVE-2020-10682 | Hig | 0.51 | 7.8 | 0.02 | Mar 20, 2020 | The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file). | ||
| CVE-2018-10517 | Hig | 0.51 | 7.2 | 0.12 | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element. | ||
| CVE-2017-1000454 | Hig | 0.51 | 7.8 | 0.01 | Jan 2, 2018 | CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1 | ||
| CVE-2017-8912 | Hig | 0.50 | 7.2 | 0.03 | May 12, 2017 | CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a… | ||
| CVE-2019-9060 | Hig | 0.49 | 7.5 | 0.02 | Sep 17, 2021 | An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read… | ||
| CVE-2011-4310 | Hig | 0.49 | 7.5 | 0.01 | Nov 26, 2019 | The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles. | ||
| CVE-2019-9692 | Med | 0.49 | 6.5 | 0.46 | Mar 11, 2019 | class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG). | ||
| CVE-2018-10083 | Hig | 0.49 | 7.5 | 0.02 | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter. | ||
| CVE-2024-1529 | Hig | 0.48 | 7.4 | 0.00 | Mar 12, 2024 | Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially… | ||
| CVE-2024-1528 | Hig | 0.48 | 7.4 | 0.00 | Mar 12, 2024 | CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted… | ||
| CVE-2024-27622 | Hig | 0.47 | 7.2 | 0.02 | Mar 5, 2024 | A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated… | ||
| CVE-2021-28998 | Hig | 0.47 | 7.2 | 0.01 | May 8, 2023 | File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file. |
- risk 0.57cvss 8.8epss 0.00
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
- risk 0.57cvss 8.8epss 0.00
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
- risk 0.57cvss 8.8epss 0.00
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page.…
- risk 0.53cvss 7.2epss 0.39
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any…
- risk 0.53cvss 7.5epss 0.13
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
- risk 0.52cvss 8.0epss 0.01
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.
- risk 0.51cvss 7.8epss 0.01
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
- risk 0.51cvss 7.8epss 0.01
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
- risk 0.51cvss 7.8epss 0.02
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).
- risk 0.51cvss 7.2epss 0.12
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.
- risk 0.51cvss 7.8epss 0.01
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
- risk 0.50cvss 7.2epss 0.03
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read…
- risk 0.49cvss 7.5epss 0.01
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
- risk 0.49cvss 6.5epss 0.46
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
- risk 0.49cvss 7.5epss 0.02
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter.
- risk 0.48cvss 7.4epss 0.00
Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially…
- risk 0.48cvss 7.4epss 0.00
CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted…
- risk 0.47cvss 7.2epss 0.02
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated…
- risk 0.47cvss 7.2epss 0.01
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
Page 2 of 8