cmsmadesimple CVE Vulnerabilities & Metrics

Focus on cmsmadesimple vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About cmsmadesimple Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with cmsmadesimple. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total cmsmadesimple CVEs: 122
Earliest CVE date: 27 Jul 2005, 04:00 UTC
Latest CVE date: 12 Mar 2024, 16:15 UTC

Latest CVE reference: CVE-2024-1529

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -80.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -80.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical cmsmadesimple CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.39

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 68
4.0-6.9 71
7.0-8.9 12
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS cmsmadesimple CVEs

These are the five CVEs with the highest CVSS scores for cmsmadesimple, sorted by severity first and recency.

All CVEs for cmsmadesimple

CVE-2024-1529 cmsmadesimple vulnerability CVSS: 0 12 Mar 2024, 16:15 UTC

Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially take over their browser session.

CVE-2024-1528 cmsmadesimple vulnerability CVSS: 0 12 Mar 2024, 16:15 UTC

CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.

CVE-2024-1527 cmsmadesimple vulnerability CVSS: 0 12 Mar 2024, 16:15 UTC

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

CVE-2023-43352 cmsmadesimple vulnerability CVSS: 0 26 Oct 2023, 22:15 UTC

An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

CVE-2023-43360 cmsmadesimple vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.

CVE-2023-43358 cmsmadesimple vulnerability CVSS: 0 23 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.

CVE-2023-43357 cmsmadesimple vulnerability CVSS: 0 20 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVE-2023-43356 cmsmadesimple vulnerability CVSS: 0 20 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.

CVE-2023-43355 cmsmadesimple vulnerability CVSS: 0 20 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.

CVE-2023-43354 cmsmadesimple vulnerability CVSS: 0 20 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.

CVE-2023-43353 cmsmadesimple vulnerability CVSS: 0 20 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.

CVE-2023-43359 cmsmadesimple vulnerability CVSS: 0 19 Oct 2023, 22:15 UTC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.

CVE-2023-43872 cmsmadesimple vulnerability CVSS: 0 28 Sep 2023, 14:15 UTC

A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-43339 cmsmadesimple vulnerability CVSS: 0 25 Sep 2023, 16:15 UTC

Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.

CVE-2023-36970 cmsmadesimple vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

CVE-2023-36969 cmsmadesimple vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

CVE-2021-28999 cmsmadesimple vulnerability CVSS: 0 08 May 2023, 14:15 UTC

SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.

CVE-2021-28998 cmsmadesimple vulnerability CVSS: 0 08 May 2023, 14:15 UTC

File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.

CVE-2021-40961 cmsmadesimple vulnerability CVSS: 6.5 09 Jun 2022, 15:15 UTC

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

CVE-2021-43154 cmsmadesimple vulnerability CVSS: 4.3 13 Apr 2022, 23:15 UTC

Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.

CVE-2022-23907 cmsmadesimple vulnerability CVSS: 4.3 28 Feb 2022, 23:15 UTC

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

CVE-2022-23906 cmsmadesimple vulnerability CVSS: 6.5 28 Feb 2022, 23:15 UTC

CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.

CVE-2020-23481 cmsmadesimple vulnerability CVSS: 3.5 22 Sep 2021, 20:15 UTC

CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.

CVE-2019-9060 cmsmadesimple vulnerability CVSS: 5.0 17 Sep 2021, 16:15 UTC

An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).

CVE-2020-22732 cmsmadesimple vulnerability CVSS: 3.5 05 Aug 2021, 17:15 UTC

CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..

CVE-2020-23241 cmsmadesimple vulnerability CVSS: 3.5 26 Jul 2021, 21:15 UTC

Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.

CVE-2020-23240 cmsmadesimple vulnerability CVSS: 3.5 26 Jul 2021, 21:15 UTC

Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.

CVE-2020-36416 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.

CVE-2020-36415 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Stylesheet" parameter under the "Stylesheets" module.

CVE-2020-36414 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "URL (slug)" or "Extra" fields under the "Add Article" feature.

CVE-2020-36413 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "Site Down" status" parameter under the "Maintenance Mode" module.

CVE-2020-36412 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.

CVE-2020-36411 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Path for the {page_image} tag:" or "Path for thumbnail field:" parameters under the "Content Editing Settings" module.

CVE-2020-36410 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter under the "Options" module.

CVE-2020-36409 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Category" parameter under the "Categories" module.

CVE-2020-36408 cmsmadesimple vulnerability CVSS: 3.5 02 Jul 2021, 18:15 UTC

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Shortcut" parameter under the "Manage Shortcuts" module.

CVE-2020-27377 cmsmadesimple vulnerability CVSS: 3.5 01 Jun 2021, 15:15 UTC

A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.

CVE-2021-28935 cmsmadesimple vulnerability CVSS: 3.5 30 Mar 2021, 12:16 UTC

CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.

CVE-2020-20138 cmsmadesimple vulnerability CVSS: 4.3 17 Dec 2020, 23:15 UTC

Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.

CVE-2020-24860 cmsmadesimple vulnerability CVSS: 3.5 01 Oct 2020, 14:15 UTC

CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.

CVE-2020-22842 cmsmadesimple vulnerability CVSS: 3.5 30 Sep 2020, 18:15 UTC

CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

CVE-2020-17462 cmsmadesimple vulnerability CVSS: 6.5 14 Aug 2020, 15:15 UTC

CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.

CVE-2020-14926 cmsmadesimple vulnerability CVSS: 3.5 19 Jun 2020, 17:15 UTC

CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.

CVE-2020-13660 cmsmadesimple vulnerability CVSS: 3.5 28 May 2020, 19:15 UTC

CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.

CVE-2020-10682 cmsmadesimple vulnerability CVSS: 6.8 20 Mar 2020, 04:15 UTC

The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).

CVE-2020-10681 cmsmadesimple vulnerability CVSS: 3.5 20 Mar 2020, 04:15 UTC

The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.

CVE-2011-4310 cmsmadesimple vulnerability CVSS: 5.0 26 Nov 2019, 23:15 UTC

The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.

CVE-2019-17630 cmsmadesimple vulnerability CVSS: 3.5 16 Oct 2019, 14:15 UTC

CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.

CVE-2019-17629 cmsmadesimple vulnerability CVSS: 3.5 16 Oct 2019, 14:15 UTC

CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.

CVE-2019-17226 cmsmadesimple vulnerability CVSS: 3.5 06 Oct 2019, 18:15 UTC

CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.

CVE-2019-1010290 cmsmadesimple vulnerability CVSS: 5.8 16 Jul 2019, 14:15 UTC

Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.

CVE-2019-11226 cmsmadesimple vulnerability CVSS: 3.5 05 Jun 2019, 18:29 UTC

CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.

CVE-2019-11513 cmsmadesimple vulnerability CVSS: 3.5 25 Apr 2019, 03:29 UTC

The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.

CVE-2019-9056 cmsmadesimple vulnerability CVSS: 6.5 11 Apr 2019, 20:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.

CVE-2019-10107 cmsmadesimple vulnerability CVSS: 3.5 26 Mar 2019, 22:29 UTC

CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.

CVE-2019-10106 cmsmadesimple vulnerability CVSS: 3.5 26 Mar 2019, 22:29 UTC

CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.

CVE-2019-10105 cmsmadesimple vulnerability CVSS: 3.5 26 Mar 2019, 22:29 UTC

CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.

CVE-2019-9061 cmsmadesimple vulnerability CVSS: 6.5 26 Mar 2019, 17:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.

CVE-2019-9059 cmsmadesimple vulnerability CVSS: 6.5 26 Mar 2019, 17:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password" feature.

CVE-2019-9058 cmsmadesimple vulnerability CVSS: 6.5 26 Mar 2019, 17:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

CVE-2019-9057 cmsmadesimple vulnerability CVSS: 6.5 26 Mar 2019, 17:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.

CVE-2019-9055 cmsmadesimple vulnerability CVSS: 6.5 26 Mar 2019, 17:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVE-2019-9053 cmsmadesimple vulnerability CVSS: 6.8 26 Mar 2019, 17:29 UTC

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

CVE-2019-10017 cmsmadesimple vulnerability CVSS: 3.5 24 Mar 2019, 22:29 UTC

CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.

CVE-2019-9693 cmsmadesimple vulnerability CVSS: 6.5 11 Mar 2019, 18:29 UTC

In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).

CVE-2019-9692 cmsmadesimple vulnerability CVSS: 4.0 11 Mar 2019, 18:29 UTC

class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).

CVE-2018-20464 cmsmadesimple vulnerability CVSS: 4.3 25 Dec 2018, 23:29 UTC

There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.

CVE-2018-19597 cmsmadesimple vulnerability CVSS: 3.5 19 Dec 2018, 19:29 UTC

CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.

CVE-2018-18271 cmsmadesimple vulnerability CVSS: 4.3 12 Oct 2018, 19:29 UTC

XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.

CVE-2018-18270 cmsmadesimple vulnerability CVSS: 4.3 12 Oct 2018, 19:29 UTC

XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.

CVE-2018-10523 cmsmadesimple vulnerability CVSS: 5.0 27 Apr 2018, 18:29 UTC

CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager/untgz.php.

CVE-2018-10522 cmsmadesimple vulnerability CVSS: 4.0 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricted access to the PHP file_get_contents function.

CVE-2018-10521 cmsmadesimple vulnerability CVSS: 4.0 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.

CVE-2018-10520 cmsmadesimple vulnerability CVSS: 8.5 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.

CVE-2018-10519 cmsmadesimple vulnerability CVSS: 6.5 27 Apr 2018, 18:29 UTC

CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this vulnerability exists because of an incorrect fix for CVE-2018-10084.

CVE-2018-10518 cmsmadesimple vulnerability CVSS: 8.5 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.

CVE-2018-10517 cmsmadesimple vulnerability CVSS: 6.5 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

CVE-2018-10516 cmsmadesimple vulnerability CVSS: 5.5 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory.

CVE-2018-10515 cmsmadesimple vulnerability CVSS: 6.5 27 Apr 2018, 18:29 UTC

In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.

CVE-2018-9921 cmsmadesimple vulnerability CVSS: 5.0 23 Apr 2018, 18:29 UTC

In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.

CVE-2018-1000158 cmsmadesimple vulnerability CVSS: 4.3 18 Apr 2018, 19:29 UTC

cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Reset Poisoning, specifically a reset URL pointing at an attacker controlled server can be created by using a host header attack.

CVE-2018-10086 cmsmadesimple vulnerability CVSS: 6.5 13 Apr 2018, 05:29 UTC

CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.

CVE-2018-10085 cmsmadesimple vulnerability CVSS: 7.5 13 Apr 2018, 05:29 UTC

CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\class.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or delete files.

CVE-2018-10084 cmsmadesimple vulnerability CVSS: 6.5 13 Apr 2018, 05:29 UTC

CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection mechanism can be bypassed.

CVE-2018-10083 cmsmadesimple vulnerability CVSS: 6.4 13 Apr 2018, 05:29 UTC

CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter.

CVE-2018-10082 cmsmadesimple vulnerability CVSS: 5.0 13 Apr 2018, 05:29 UTC

CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or /lib/tasks/class.CmsSecurityCheck.task.php.

CVE-2018-10081 cmsmadesimple vulnerability CVSS: 5.0 13 Apr 2018, 05:29 UTC

CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.

CVE-2018-10033 cmsmadesimple vulnerability CVSS: 3.5 11 Apr 2018, 19:29 UTC

CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.

CVE-2018-10032 cmsmadesimple vulnerability CVSS: 3.5 11 Apr 2018, 19:29 UTC

CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.

CVE-2018-10031 cmsmadesimple vulnerability CVSS: 6.8 11 Apr 2018, 19:29 UTC

CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.

CVE-2018-10030 cmsmadesimple vulnerability CVSS: 6.8 11 Apr 2018, 19:29 UTC

CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.

CVE-2018-10029 cmsmadesimple vulnerability CVSS: 3.5 11 Apr 2018, 19:29 UTC

CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.

CVE-2018-1000092 cmsmadesimple vulnerability CVSS: 6.8 13 Mar 2018, 15:29 UTC

CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.

CVE-2018-1000094 cmsmadesimple vulnerability CVSS: 6.5 13 Mar 2018, 01:29 UTC

CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.

CVE-2018-8058 cmsmadesimple vulnerability CVSS: 3.5 12 Mar 2018, 03:29 UTC

CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.

CVE-2018-7893 cmsmadesimple vulnerability CVSS: 3.5 12 Mar 2018, 03:29 UTC

CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.

CVE-2018-7448 cmsmadesimple vulnerability CVSS: 8.5 26 Feb 2018, 17:29 UTC

Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

CVE-2018-5965 cmsmadesimple vulnerability CVSS: 3.5 25 Jan 2018, 16:29 UTC

CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.

CVE-2018-5964 cmsmadesimple vulnerability CVSS: 3.5 25 Jan 2018, 16:29 UTC

CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.

CVE-2018-5963 cmsmadesimple vulnerability CVSS: 3.5 25 Jan 2018, 16:29 UTC

CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.

CVE-2017-1000454 cmsmadesimple vulnerability CVSS: 4.6 02 Jan 2018, 17:29 UTC

CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1

CVE-2017-1000453 cmsmadesimple vulnerability CVSS: 7.5 02 Jan 2018, 17:29 UTC

CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.

CVE-2017-17735 cmsmadesimple vulnerability CVSS: 5.0 18 Dec 2017, 06:29 UTC

CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.

CVE-2017-17734 cmsmadesimple vulnerability CVSS: 5.0 18 Dec 2017, 06:29 UTC

CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.

CVE-2017-16799 cmsmadesimple vulnerability CVSS: 3.5 12 Nov 2017, 18:29 UTC

In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php during addition of a category, a related issue to CVE-2010-3882.

CVE-2017-16798 cmsmadesimple vulnerability CVSS: 3.5 12 Nov 2017, 18:29 UTC

In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.

CVE-2017-16784 cmsmadesimple vulnerability CVSS: 4.3 10 Nov 2017, 23:29 UTC

In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.

CVE-2017-16783 cmsmadesimple vulnerability CVSS: 7.5 10 Nov 2017, 23:29 UTC

In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.

CVE-2017-11405 cmsmadesimple vulnerability CVSS: 4.0 18 Jul 2017, 00:29 UTC

In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.

CVE-2017-11404 cmsmadesimple vulnerability CVSS: 4.0 18 Jul 2017, 00:29 UTC

In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.

CVE-2017-9668 cmsmadesimple vulnerability CVSS: 4.3 18 Jun 2017, 21:29 UTC

In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.

CVE-2017-8912 cmsmadesimple vulnerability CVSS: 6.5 12 May 2017, 07:29 UTC

CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.

CVE-2017-7257 cmsmadesimple vulnerability CVSS: 3.5 24 Mar 2017, 15:59 UTC

XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.

CVE-2017-7256 cmsmadesimple vulnerability CVSS: 3.5 24 Mar 2017, 15:59 UTC

XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.

CVE-2017-7255 cmsmadesimple vulnerability CVSS: 3.5 24 Mar 2017, 15:59 UTC

XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.

CVE-2017-6556 cmsmadesimple vulnerability CVSS: 3.5 09 Mar 2017, 09:59 UTC

Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

CVE-2017-6555 cmsmadesimple vulnerability CVSS: 3.5 09 Mar 2017, 09:59 UTC

Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").

CVE-2017-6072 cmsmadesimple vulnerability CVSS: 5.0 21 Feb 2017, 07:59 UTC

CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.

CVE-2017-6071 cmsmadesimple vulnerability CVSS: 5.0 21 Feb 2017, 07:59 UTC

CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.

CVE-2017-6070 cmsmadesimple vulnerability CVSS: 7.5 21 Feb 2017, 07:59 UTC

CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.

CVE-2016-7904 cmsmadesimple vulnerability CVSS: 6.0 16 Jan 2017, 06:59 UTC

Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.

CVE-2016-2784 cmsmadesimple vulnerability CVSS: 2.6 26 May 2016, 14:59 UTC

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

CVE-2014-2245 cmsmadesimple vulnerability CVSS: 6.0 05 Mar 2014, 16:37 UTC

SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php. NOTE: some of these details are obtained from third party information.

CVE-2014-2092 cmsmadesimple vulnerability CVSS: 4.3 02 Mar 2014, 17:55 UTC

Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

CVE-2014-0334 cmsmadesimple vulnerability CVSS: 3.5 02 Mar 2014, 17:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitrary web script or HTML via (1) the group parameter to admin/addgroup.php, (2) the htmlblob parameter to admin/addhtmlblob.php, the (3) title or (4) url parameter to admin/addbookmark.php, (5) the stylesheet_name parameter to admin/copystylesheet.php, (6) the template_name parameter to admin/copytemplate.php, the (7) title or (8) url parameter to admin/editbookmark.php, (9) the template parameter to admin/listtemplates.php, or (10) the css_name parameter to admin/listcss.php, a different issue than CVE-2014-2092.

CVE-2013-3929 cmsmadesimple vulnerability CVSS: 2.1 09 Dec 2013, 16:55 UTC

Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.

CVE-2013-4167 cmsmadesimple vulnerability CVSS: 4.3 11 Oct 2013, 22:55 UTC

Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) before 1.11.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-6064 cmsmadesimple vulnerability CVSS: 3.5 03 Dec 2012, 21:55 UTC

Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

CVE-2012-5450 cmsmadesimple vulnerability CVSS: 6.8 03 Dec 2012, 21:55 UTC

Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deld parameter.

CVE-2012-1992 cmsmadesimple vulnerability CVSS: 4.3 11 Apr 2012, 10:39 UTC

Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template).

CVE-2011-3718 cmsmadesimple vulnerability CVSS: 5.0 23 Sep 2011, 23:55 UTC

CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/TinyMCE/TinyMCE.module.php and certain other files. NOTE: this might overlap CVE-2007-5444.

CVE-2010-4663 cmsmadesimple vulnerability CVSS: 10.0 08 Jun 2011, 10:36 UTC

Unspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack vectors.

CVE-2010-3884 cmsmadesimple vulnerability CVSS: 6.8 08 Oct 2010, 21:00 UTC

Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2010-3883 cmsmadesimple vulnerability CVSS: 6.8 08 Oct 2010, 21:00 UTC

Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make permission modifications.

CVE-2010-3882 cmsmadesimple vulnerability CVSS: 4.3 08 Oct 2010, 21:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module.

CVE-2010-2797 cmsmadesimple vulnerability CVSS: 7.5 08 Oct 2010, 21:00 UTC

Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.

CVE-2010-1482 cmsmadesimple vulnerability CVSS: 4.3 12 May 2010, 16:05 UTC

Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.

CVE-2008-5642 cmsmadesimple vulnerability CVSS: 5.0 17 Dec 2008, 17:30 UTC

Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a cms_language cookie.

CVE-2007-6656 cmsmadesimple vulnerability CVSS: 7.5 04 Jan 2008, 11:46 UTC

SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.

CVE-2007-5441 cmsmadesimple vulnerability CVSS: 6.5 14 Oct 2007, 18:17 UTC

CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.

CVE-2007-5444 cmsmadesimple vulnerability CVSS: 5.0 14 Oct 2007, 18:17 UTC

CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files.

CVE-2007-5443 cmsmadesimple vulnerability CVSS: 4.3 14 Oct 2007, 18:17 UTC

Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags.

CVE-2007-5442 cmsmadesimple vulnerability CVSS: 3.5 14 Oct 2007, 18:17 UTC

CMS Made Simple 1.1.3.1 does not check the permissions assigned to users who attempt uploads, which allows remote authenticated users to upload unspecified files via unknown vectors.

CVE-2007-5056 cmsmadesimple vulnerability CVSS: 6.8 24 Sep 2007, 22:17 UTC

Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.

CVE-2007-2473 cmsmadesimple vulnerability CVSS: 7.5 02 May 2007, 23:19 UTC

SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.

CVE-2007-0610 cmsmadesimple vulnerability CVSS: 6.8 31 Jan 2007, 01:28 UTC

Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML via the sender parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2007-0551 cmsmadesimple vulnerability CVSS: 7.5 29 Jan 2007, 17:28 UTC

Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters.

CVE-2006-6844 cmsmadesimple vulnerability CVSS: 6.8 31 Dec 2006, 05:00 UTC

Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the user comment form.

CVE-2006-6845 cmsmadesimple vulnerability CVSS: 6.8 31 Dec 2006, 05:00 UTC

Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.

CVE-2005-3083 cmsmadesimple vulnerability CVSS: 4.3 27 Sep 2005, 20:03 UTC

Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2005-2846 cmsmadesimple vulnerability CVSS: 7.5 08 Sep 2005, 10:03 UTC

PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.

CVE-2005-2392 cmsmadesimple vulnerability CVSS: 4.3 27 Jul 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.