Home/Product/cmsmadesimple cms made simple
Product

cmsmadesimple cms made simple

158 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-63678
all versions
An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22
7.2HIGH
CVE-2025-5153
all versions
A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown pr
3.5LOW
CVE-2024-1529
all versions
Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scrip
7.4HIGH
CVE-2024-1528
all versions
CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vuln
7.4HIGH
CVE-2024-1527
all versions
Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated us
9.8CRITICAL
CVE-2024-27625
all versions
CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module
4.8MEDIUM
CVE-2024-27623
all versions
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design
5.9MEDIUM
CVE-2024-27622
all versions
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.
7.2HIGH
CVE-2023-43352
all versions
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager
7.8HIGH
CVE-2023-43360
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43358
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43357
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43356
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43355
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43354
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43353
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43359
all versions
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted scrip
5.4MEDIUM
CVE-2023-43872
all versions
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scriptin
5.4MEDIUM
CVE-2023-43339
all versions
Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted
6.1MEDIUM
CVE-2023-36970
all versions
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HT
5.4MEDIUM
CVE-2023-36969
all versions
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
8.8HIGH
CVE-2021-28999
<= 2.2.15
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sor
8.8HIGH
CVE-2021-28998
<= 2.2.15
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted
7.2HIGH
CVE-2021-40961
<= 2.2.15
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is conc
8.8HIGH
CVE-2021-43154
all versions
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in modulein
6.1MEDIUM
CVE-2022-23907
all versions
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmess
6.1MEDIUM
CVE-2022-23906
all versions
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. T
7.2HIGH
CVE-2020-23481
all versions
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbi
5.4MEDIUM
CVE-2019-9060
all versions
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions mod
7.5HIGH
CVE-2020-22732
all versions
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
4.8MEDIUM
CVE-2020-23241
all versions
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
4.8MEDIUM
CVE-2020-23240
all versions
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
4.8MEDIUM
CVE-2020-36416
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36415
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36414
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36413
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36412
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36411
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36410
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36409
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-36408
all versions
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scr
5.4MEDIUM
CVE-2020-27377
all versions
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simp
4.8MEDIUM
CVE-2021-28935
all versions
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferen
5.4MEDIUM
CVE-2020-20138
all versions
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
6.1MEDIUM
CVE-2020-24860
all versions
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payl
5.4MEDIUM
CVE-2020-22842
< 2.2.15
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterfa
5.4MEDIUM
CVE-2020-17462
all versions
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related i
7.8HIGH
CVE-2020-14926
all versions
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
5.4MEDIUM
CVE-2020-13660
<= 2.2.14
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
4.8MEDIUM
CVE-2020-10682
all versions
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] t
7.8HIGH
CVE-2020-10681
all versions
The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.p
5.4MEDIUM
CVE-2011-4310
< 1.9.4.3
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
7.5HIGH
CVE-2019-17630
all versions
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
4.8MEDIUM
CVE-2019-17629
all versions
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" sc
4.8MEDIUM
CVE-2019-17226
all versions
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
4.8MEDIUM
CVE-2019-1010290
<= 0.4.1
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to r
6.1MEDIUM
CVE-2019-11226
all versions
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content - Content Manager - News.
5.4MEDIUM
CVE-2019-11513
<= 2.2.10
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
4.8MEDIUM
CVE-2019-9056
all versions
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or cl
8.8HIGH
CVE-2019-10107
all versions
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences - My Accoun
5.4MEDIUM
CVE-2019-10106
all versions
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "S
5.4MEDIUM
CVE-2019-10105
all versions
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a
5.4MEDIUM
CVE-2019-9061
<= 2.2.8
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possib
8.8HIGH
CVE-2019-9059
<= 2.2.8
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by m
7.2HIGH
CVE-2019-9058
<= 2.2.8
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a cr
7.2HIGH
CVE-2019-9057
<= 2.2.8
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an un
8.8HIGH
CVE-2019-9055
<= 2.2.8
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.a
8.8HIGH
CVE-2019-9053
all versions
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthent
8.1HIGH
CVE-2019-10017
all versions
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the
5.4MEDIUM
CVE-2019-9693
< 2.2.10
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the func
8.8HIGH
CVE-2019-9692
< 2.2.10
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file
6.5MEDIUM
CVE-2018-20464
all versions
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an a
6.1MEDIUM
CVE-2018-19597
all versions
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
4.8MEDIUM
CVE-2018-18271
all versions
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content--News--Add Article
6.1MEDIUM
CVE-2018-18270
all versions
XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content--News--Add Arti
6.1MEDIUM
CVE-2018-10523
<= 2.2.7
CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_te
5.3MEDIUM
CVE-2018-10522
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclo
4.9MEDIUM
CVE-2018-10521
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vul
2.7LOW
CVE-2018-10520
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion
6.5MEDIUM
CVE-2018-10519
all versions
CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the
8.8HIGH
CVE-2018-10518
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion v
6.5MEDIUM
CVE-2018-10517
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vu
7.2HIGH
CVE-2018-10516
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disc
6.5MEDIUM
CVE-2018-10515
<= 2.2.7
In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vuln
7.2HIGH
CVE-2018-9921
all versions
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outsid
5.3MEDIUM
CVE-2018-1000158
all versions
cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "
8.8HIGH
CVE-2018-10086
<= 2.2.7
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implem
7.2HIGH
CVE-2018-10085
<= 2.2.6
CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib
9.8CRITICAL
CVE-2018-10084
<= 2.2.6
CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging
8.8HIGH
CVE-2018-10083
<= 2.2.7
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory trave
7.5HIGH
CVE-2018-10082
<= 2.2.7
CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting w
5.3MEDIUM
CVE-2018-10081
<= 2.2.7
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared,
9.8CRITICAL
CVE-2018-10033
<= 2.2.7
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
4.8MEDIUM
CVE-2018-10032
<= 2.2.7
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
4.8MEDIUM
CVE-2018-10031
<= 2.2.7
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
8.8HIGH
CVE-2018-10030
<= 2.2.7
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
8.8HIGH
CVE-2018-10029
<= 2.2.7
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepen
4.8MEDIUM
CVE-2018-1000092
all versions
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can re
8.8HIGH
CVE-2018-1000094
all versions
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenti
7.2HIGH
CVE-2018-8058
all versions
CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
4.8MEDIUM
CVE-2018-7893
all versions
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
4.8MEDIUM
CVE-2018-7448
all versions
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers
7.5HIGH
CVE-2018-5965
all versions
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
4.8MEDIUM
CVE-2018-5964
all versions
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.
4.8MEDIUM
CVE-2018-5963
all versions
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.
4.8MEDIUM
CVE-2017-1000454
< 2.2
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file rea
7.8HIGH
CVE-2017-1000453
< 2.2
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthentic
9.8CRITICAL
CVE-2017-17735
< 2.2.5
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
9.8CRITICAL
CVE-2017-17734
< 2.2.5
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
9.8CRITICAL
CVE-2017-16799
all versions
In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/modul
5.4MEDIUM
CVE-2017-16798
all versions
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions t
5.4MEDIUM
CVE-2017-16784
all versions
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
6.1MEDIUM
CVE-2017-16783
all versions
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
9.8CRITICAL
CVE-2017-11405
all versions
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to adm
4.9MEDIUM
CVE-2017-11404
all versions
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/mod
4.9MEDIUM
CVE-2017-9668
all versions
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS
6.1MEDIUM
CVE-2017-8912
all versions
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to a
7.2HIGH
CVE-2017-7257
all versions
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content--News--Add Article" feature via the m1_content parameter. Someone must lo
5.4MEDIUM
CVE-2017-7256
all versions
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content--News--Add Article" feature via the m1_summary parameter. Someone must lo
5.4MEDIUM
CVE-2017-7255
all versions
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content--News--Add Article" feature via the m1_title parameter. Someone must logi
5.4MEDIUM
CVE-2017-6556
all versions
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary we
5.4MEDIUM
CVE-2017-6555
all versions
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users
5.4MEDIUM
CVE-2017-6072
<= 1.12.2
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks
5.3MEDIUM
CVE-2017-6071
<= 1.12.2
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks
5.3MEDIUM
CVE-2017-6070
<= 1.12.2
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_fo
9.8CRITICAL
CVE-2016-7904
<= 2.1.5
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authenticati
8.0HIGH
CVE-2016-2784
all versions
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache po
4.7MEDIUM
CVE-2014-2245
<= 1.11.9
SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with th
CVE-2014-2092
all versions
Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote
CVE-2014-0334
all versions
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitrary web sc
CVE-2013-3929
all versions
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated user
CVE-2013-4167
<= 1.11.6
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) before 1.11.7 allows remote attackers to inject arbitrary web
CVE-2012-6064
<= 1.11.2
Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows rem
CVE-2012-5450
<= 1.11.2
Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and e
CVE-2012-1992
<= 1.10.3
Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to in
CVE-2011-3718
all versions
CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which r
CVE-2010-4663
<= 1.9
Unspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack vectors.
CVE-2010-3884
<= 1.8.1
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authent
CVE-2010-3883
<= 1.7.1
Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows
CVE-2010-3882
<= 1.7.1
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrar
CVE-2010-2797
<= 1.6.8
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to incl
CVE-2010-1482
<= 1.7
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow
CVE-2008-5642
all versions
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via
CVE-2008-2267
all versions
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier all
CVE-2007-6656
<= 1.2.2
SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers
CVE-2007-5444
all versions
CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files.
CVE-2007-5443
all versions
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web scri
CVE-2007-5442
all versions
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users who attempt uploads, which allows remote authenticated us
CVE-2007-5441
all versions
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated use
CVE-2007-5056
all versions
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made S
CVE-2007-2473
<= 1.0.5
SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQ
CVE-2007-0610
all versions
Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary
CVE-2007-0551
all versions
Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary
CVE-2006-6845
all versions
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web scr
CVE-2006-6844
all versions
Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to i
CVE-2005-3083
all versions
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web scri
CVE-2005-2846
all versions
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitra
CVE-2005-2392
all versions
Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web
threatengine.sh