← Back

Simplece

simplece

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Simplece
simplece

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simplece
1Simplece
May 13, 2026
Jun 15, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In SimpleCE 2.3.0, an authenticated XSS vulnerability was found on index.php/content/text/1?return_url=[XSS] exploitable as a regular or admin user.
1Simplece
1Simplece
May 13, 2026
Jun 15, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.