CMS Made Simple is a lightweight content management system with a narrowly scoped product footprint centered on web application deployment and site administration. The durable signal in its vulnerability profile centers on improper input validation in the CMS core, reflecting common web application handling challenges. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cms Made Simple over time
Signals from CVEs in this vendor scope (158 CVEs).
158 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9053HIGH An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_i | Mar 26, 2019 | 8.1 | 68 | NO | YES |
CVE-2018-1000094HIGH CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to | Mar 13, 2018 | 7.2 | 65 | NO | YES |
CVE-2023-36969HIGH CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | Jul 6, 2023 | 8.8 | 59 | NO | YES |
CVE-2019-9692MEDIUM class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG). | Mar 11, 2019 | 6.5 | 59 | NO | YES |
CVE-2017-16783CRITICAL In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. | Nov 10, 2017 | 9.8 | 45 | NO | YES |
CVE-2018-7448HIGH Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" p | Feb 26, 2018 | 7.5 | 41 | NO | YES |
CVE-2007-5056MEDIUM Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open- | Sep 24, 2007 | 6.8 | 40 | NO | YES |
CVE-2018-10517HIGH In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because | Apr 27, 2018 | 7.2 | 39 | NO | YES |
CVE-2019-9055HIGH An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user | Mar 26, 2019 | 8.8 | 37 | NO | YES |
CVE-2017-8912HIGH CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunc | May 12, 2017 | 7.2 | 36 | NO | YES |
Signals from CVEs in this vendor scope (158 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cms Made Simple.
Media articles that mention a CVE ID that affects a product developed by Cms Made Simple — matched by CVE ID, not by vendor name.