Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cmsmadesimple

First CVE: Jul 27, 2005Active for: 21 yearsTotal CVEs: 158
38.9
VTI Score
Medium

CMS Made Simple is a niche web content management system and associated plugin ecosystem that has accumulated a moderate disclosure volume despite its focused product footprint. The vendor's vulnerabilities concentrate in web-application-layer weakness classes including cross-site scripting, unrestricted file uploads, code injection, and exposure of sensitive information—patterns endemic to PHP-based CMS platforms and their plugin architectures. Notably, this vendor's disclosures have an elevated tendency to acquire public exploit code, which reflects the relative simplicity of many web-application flaws and the active interest in compromising web-facing CMS installations. Defenders should treat CMS Made Simple instances as requiring close vendor monitoring, particularly when the system is internet-exposed or handles sensitive content, and should prioritize timely patching given the public availability of exploit tooling. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
158
Total CVEs
More Total CVEs than 100% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cmsmadesimple over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2005
20 years ago
Most Recent CVE
Nov 10, 2025
258 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (158 CVEs).

158 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9053HIGH
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_i
Mar 26, 20198.174NOYES
CVE-2018-1000094HIGH
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to
Mar 13, 20187.265NOYES
CVE-2023-36969HIGH
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Jul 6, 20238.859NOYES
CVE-2019-9692MEDIUM
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
Mar 11, 20196.559NOYES
CVE-2017-16783CRITICAL
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Nov 10, 20179.845NOYES
CVE-2018-7448HIGH
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" p
Feb 26, 20187.541NOYES
CVE-2007-5056MEDIUM
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-
Sep 24, 20076.840NOYES
CVE-2018-10517HIGH
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because
Apr 27, 20187.239NOYES
CVE-2019-9055HIGH
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user
Mar 26, 20198.837NOYES
CVE-2017-8912HIGH
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunc
May 12, 20177.236NOYES
View all 158 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products158 CVEs
65%
27%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (2.5%)
Network123 (77.8%)
Unknown31 (19.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low124 (78.5%)
High3 (1.9%)
Unknown31 (19.6%)
User Interaction
None49 (31.0%)
Unknown31 (19.6%)
Required78 (49.4%)
Privileges Required
Low53 (33.5%)
High39 (24.7%)
None35 (22.2%)
Unknown31 (19.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (158 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
2.5% of CVEs· 97th percentile
Nuclei
1 CVE
0.6% of CVEs· 95th percentile
ExploitDB
19 CVEs
12.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cmsmadesimple.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cmsmadesimple — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cmsmadesimple's Products

View all 6 CNAs →

Top CWEs