Cms Made Simple

Vendor:

First CVE: Jul 27, 2005 · Active for 21 years

156
Total CVEs
More Total CVEs than 99% of tracked products
8.2
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cms Made Simple over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2005
20 years ago
Most Recent CVE
May 25, 2025
428 days ago

CVE Severity & Scoring

Cms Made Simple156 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local4 (2.6%)
Network121 (77.6%)
Unknown31 (19.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low122 (78.2%)
High3 (1.9%)
Unknown31 (19.9%)
User Interaction
None48 (30.8%)
Unknown31 (19.9%)
Required77 (49.4%)
Privileges Required
Low53 (34.0%)
High38 (24.4%)
None34 (21.8%)
Unknown31 (19.9%)

Top CVEs

Signals from CVEs in this product scope (156 CVEs).

156 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_i
Mar 26, 20198.174NOYES
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to
Mar 13, 20187.265NOYES
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Jul 6, 20238.859NOYES
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
Mar 11, 20196.559NOYES
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Nov 10, 20179.845NOYES
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" p
Feb 26, 20187.541NOYES
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-
Sep 24, 20076.840NOYES
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because
Apr 27, 20187.239NOYES
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user
Mar 26, 20198.837NOYES
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunc
May 12, 20177.236NOYES

Exploit Exposure

Signals from CVEs in this product scope (156 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
12.2% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (156 CVEs).

Media Mentions

Signals from CVEs in this product scope (156 CVEs).

Top CNAs Publishing CVEs For Cms Made Simple

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
beta_214.31.4%00
beta_114.31.4%00
2.727.21.3%00
2.4_beta14.31.4%00
2.414.31.4%00
2.314.31.4%00
2.2.857.114.5%01
2.2.757.01.1%00
2.2.624.80.5%00
2.2.556.18.7%01
2.2.416.12.9%00
2.2.3.125.40.7%00
2.2.2126.01.1%00
2.2.235.30.8%00
2.2.1936.00.9%00
2.2.18115.70.5%00
2.2.1727.124.9%01
2.2.1546.21.3%01
2.2.14205.60.6%00
2.2.1326.61.3%00