Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cmsimple

First CVE: Jun 10, 2008Active for: 18 yearsTotal CVEs: 20
40.4
VTI Score
High

Cmsimple is a modestly represented content-management platform with a narrow product line centered on its flagship Cmsimple and Cmsimple Classic applications, which serve as lightweight alternatives to larger CMS deployments. Vulnerabilities affecting the vendor skew toward moderate severity outcomes and cluster consistently around web-application input handling and file-access control, with cross-site scripting, path traversal, PHP remote file inclusion, and code-injection flaws forming the core recurring pattern. These weakness classes are endemic to PHP-based CMS platforms and reflect the inherent challenges of sanitizing user input and controlling file-system access in web-facing applications. Defenders should treat Cmsimple instances as requiring regular patching and input validation audits, particularly where user-generated content or file uploads are permitted; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cmsimple over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 10, 2008
18 years ago
Most Recent CVE
Dec 23, 2025
213 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-2650MEDIUM
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a
Jun 10, 20086.846NOYES
CVE-2021-43741CRITICAL
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
Apr 13, 20229.832NONO
CVE-2021-47735HIGH
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit t
Dec 23, 20258.828NONO
CVE-2024-58280HIGH
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append '
Dec 10, 20258.828NONO
CVE-2021-47734HIGH
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can lev
Dec 23, 20257.824NONO
CVE-2024-57548CRITICAL
CMSimple 5.16 allows the user to edit log.php file via print page.
Jan 27, 20259.124NONO
CVE-2021-47733MEDIUM
CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts
Dec 23, 20256.121NONO
CVE-2021-47732MEDIUM
CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place
Dec 23, 20256.121NONO
CVE-2024-33423HIGH
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Lo
May 1, 20247.421NONO
CVE-2024-57549HIGH
CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
Jan 27, 20257.520NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
50%
40%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.0%)
Network17 (85.0%)
Unknown2 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High0 (0.0%)
Unknown2 (10.0%)
User Interaction
None9 (45.0%)
Unknown2 (10.0%)
Required9 (45.0%)
Privileges Required
Low5 (25.0%)
High3 (15.0%)
None10 (50.0%)
Unknown2 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.0% of CVEs· 96th percentile
ExploitDB
1 CVE
5.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cmsimple.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cmsimple — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cmsimple's Products

View all 2 CNAs →

Top CWEs