VYPR

Stupid Simple CMS

by codelyfe

CVEs (11)

  • CVE-2024-27689HigMar 1, 2024
    risk 0.57cvss 8.8epss 0.00

    Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.

  • CVE-2024-22715HigJan 17, 2024
    risk 0.57cvss 8.8epss 0.00

    Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.

  • CVE-2023-6901HigDec 17, 2023
    risk 0.48cvss 7.3epss 0.03

    A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an unknown part of the file /terminal/handle-command.php of the component HTTP POST Request Handler. The manipulation of the argument command with the input…

  • CVE-2024-27559MedMar 1, 2024
    risk 0.41cvss 6.3epss 0.00

    Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

  • CVE-2024-27558MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.

  • CVE-2024-22714MedJan 17, 2024
    risk 0.40cvss 6.1epss 0.00

    Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.

  • CVE-2023-6902MedDec 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed…

  • CVE-2023-7041MedDec 21, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'.…

  • CVE-2023-6907MedDec 18, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /file-manager/delete.php of the component Deletion Interface. The manipulation of the argument file leads…

  • CVE-2023-7040MedDec 21, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The…

  • CVE-2024-3202LowApr 2, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack may…