Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cms Made Simple

First CVE: Jul 27, 2005Active for: 21 yearsTotal CVEs: 158

CMS Made Simple is a lightweight content management system with a narrowly scoped product footprint centered on web application deployment and site administration. The durable signal in its vulnerability profile centers on improper input validation in the CMS core, reflecting common web application handling challenges. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
158
Total CVEs
Bottom 1%
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cms Made Simple over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2005
20 years ago
Most Recent CVE
Nov 10, 2025
257 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (158 CVEs).

158 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9053HIGH
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_i
Mar 26, 20198.168NOYES
CVE-2018-1000094HIGH
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to
Mar 13, 20187.265NOYES
CVE-2023-36969HIGH
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Jul 6, 20238.859NOYES
CVE-2019-9692MEDIUM
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
Mar 11, 20196.559NOYES
CVE-2017-16783CRITICAL
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Nov 10, 20179.845NOYES
CVE-2018-7448HIGH
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" p
Feb 26, 20187.541NOYES
CVE-2007-5056MEDIUM
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-
Sep 24, 20076.840NOYES
CVE-2018-10517HIGH
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because
Apr 27, 20187.239NOYES
CVE-2019-9055HIGH
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user
Mar 26, 20198.837NOYES
CVE-2017-8912HIGH
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunc
May 12, 20177.236NOYES
View all 158 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products158 CVEs
65%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (2.5%)
Network123 (77.8%)
Unknown31 (19.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low124 (78.5%)
High3 (1.9%)
Unknown31 (19.6%)
User Interaction
None49 (31.0%)
Unknown31 (19.6%)
Required78 (49.4%)
Privileges Required
Low53 (33.5%)
High39 (24.7%)
None35 (22.2%)
Unknown31 (19.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (158 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
2.5% of CVEs· Bottom 1%
Nuclei
1 CVE
0.6% of CVEs· Bottom 1%
ExploitDB
19 CVEs
12.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cms Made Simple.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cms Made Simple — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cms Made Simple's Products

View all 6 CNAs →

Top CWEs