Vulnerabilities > Cmsmadesimple > CMS Made Simple > 2.2.15
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-13 | CVE-2021-43154 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.15 Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php. | 6.1 |
2022-02-28 | CVE-2022-23906 | Unrestricted Upload of File with Dangerous Type vulnerability in Cmsmadesimple CMS Made Simple 2.2.15 CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. | 7.2 |
2022-02-28 | CVE-2022-23907 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.15 CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage. | 6.1 |
2021-03-30 | CVE-2021-28935 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.15 CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. | 5.4 |
2018-01-02 | CVE-2017-1000454 | Injection vulnerability in Cmsmadesimple CMS Made Simple CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1 | 7.8 |
2018-01-02 | CVE-2017-1000453 | Injection vulnerability in Cmsmadesimple CMS Made Simple CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution. | 9.8 |