Cmsimple is a modestly represented content-management platform with a narrow product line centered on its flagship Cmsimple and Cmsimple Classic applications, which serve as lightweight alternatives to larger CMS deployments. Vulnerabilities affecting the vendor skew toward moderate severity outcomes and cluster consistently around web-application input handling and file-access control, with cross-site scripting, path traversal, PHP remote file inclusion, and code-injection flaws forming the core recurring pattern. These weakness classes are endemic to PHP-based CMS platforms and reflect the inherent challenges of sanitizing user input and controlling file-system access in web-facing applications. Defenders should treat Cmsimple instances as requiring regular patching and input validation audits, particularly where user-generated content or file uploads are permitted; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cmsimple over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2650MEDIUM Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a | Jun 10, 2008 | 6.8 | 46 | NO | YES |
CVE-2021-43741CRITICAL CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution. | Apr 13, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-47735HIGH CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit t | Dec 23, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-58280HIGH CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ' | Dec 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2021-47734HIGH CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can lev | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2024-57548CRITICAL CMSimple 5.16 allows the user to edit log.php file via print page. | Jan 27, 2025 | 9.1 | 24 | NO | NO |
CVE-2021-47733MEDIUM CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts | Dec 23, 2025 | 6.1 | 21 | NO | NO |
CVE-2021-47732MEDIUM CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place | Dec 23, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-33423HIGH Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Lo | May 1, 2024 | 7.4 | 21 | NO | NO |
CVE-2024-57549HIGH CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request. | Jan 27, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cmsimple.
Media articles that mention a CVE ID that affects a product developed by Cmsimple — matched by CVE ID, not by vendor name.