Cmsimple XH is a lightweight, open-source content management system designed for small to medium websites, with a narrowly focused vulnerability footprint centered on its single primary product. The exposure observed reflects the application-layer attack surface typical of web-based CMS platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cmsimple Xh over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42645CRITICAL CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to ge | May 10, 2022 | 10.0 | 32 | NO | NO |
CVE-2021-47736HIGH CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. | Dec 23, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-63589HIGH A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the genera | Nov 6, 2025 | 7.1 | 24 | NO | NO |
CVE-2025-63588HIGH An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's | Nov 6, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-34452MEDIUM CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document. | Jun 21, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cmsimple Xh.
Media articles that mention a CVE ID that affects a product developed by Cmsimple Xh — matched by CVE ID, not by vendor name.