← Back

Cmsmadesimple

cmsmadesimple

157 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Form Builder
form_builder
Cmsmadesimple
cmsmadesimple
Bable\
bable\
File Manager
file_manager

CVEs (157)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
May 8, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
May 8, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using t...Show more
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Feb 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Sep 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and throug...Show more
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Aug 5, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Stylesheet" parameter un...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Stylesheet" parameter under the "Stylesheets" module.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "URL (slug)" or "Extra" fields under t...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "URL (slug)" or "Extra" fields under the "Add Article" feature.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "Site Down" status" parameter under the "Maintenance Mode" module.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin S...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Path for the {page_image} tag:" or "P...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Path for the {page_image} tag:" or "Path for thumbnail field:" parameters under the "Content Editing Settings" module.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter under the "Options" module.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Category" parameter under the "Ca...Show more
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Category" parameter under the "Categories" module.Show less