Vulnerabilities > Cmsmadesimple > CMS Made Simple > 2.2.7

DATE CVE VULNERABILITY TITLE RISK
2018-04-11 CVE-2018-10033 Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
network
low complexity
cmsmadesimple CWE-79
4.8
2018-04-11 CVE-2018-10032 Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
network
low complexity
cmsmadesimple CWE-79
4.8
2018-04-11 CVE-2018-10031 Cross-Site Request Forgery (CSRF) vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
network
low complexity
cmsmadesimple CWE-352
8.8
2018-04-11 CVE-2018-10030 Cross-Site Request Forgery (CSRF) vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
network
low complexity
cmsmadesimple CWE-352
8.8
2018-04-11 CVE-2018-10029 Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
network
low complexity
cmsmadesimple CWE-79
4.8
2018-01-02 CVE-2017-1000454 Injection vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
local
low complexity
cmsmadesimple CWE-74
7.8
2018-01-02 CVE-2017-1000453 Injection vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
network
low complexity
cmsmadesimple CWE-74
critical
9.8