Vulnerabilities > Cmsmadesimple
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-20 | CVE-2023-43357 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.18 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component. | 5.4 |
2023-10-19 | CVE-2023-43359 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.18 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component. | 5.4 |
2023-09-28 | CVE-2023-43872 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.18 A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). | 5.4 |
2023-09-25 | CVE-2023-43339 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.18 Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components. | 6.1 |
2023-07-06 | CVE-2023-36969 | Unrestricted Upload of File with Dangerous Type vulnerability in Cmsmadesimple CMS Made Simple 2.2.17 CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | 8.8 |
2023-07-06 | CVE-2023-36970 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.17 A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function. | 5.4 |
2023-05-08 | CVE-2021-28998 | Unrestricted Upload of File with Dangerous Type vulnerability in Cmsmadesimple CMS Made Simple File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file. | 7.2 |
2023-05-08 | CVE-2021-28999 | SQL Injection vulnerability in Cmsmadesimple CMS Made Simple SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php. | 8.8 |
2022-06-09 | CVE-2021-40961 | SQL Injection vulnerability in Cmsmadesimple CMS Made Simple CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. | 8.8 |
2022-04-13 | CVE-2021-43154 | Cross-site Scripting vulnerability in Cmsmadesimple CMS Made Simple 2.2.15 Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php. | 6.1 |