Cms Made Simple
Vendor:
First CVE: Jul 27, 2005 · Active for 21 years
156
Total CVEs
More Total CVEs than 99% of tracked products
8.2
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cms Made Simple over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2005
20 years ago
Most Recent CVE
May 25, 2025
428 days ago
CVE Severity & Scoring
Cms Made Simple156 CVEs
65%
27%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (2.6%)
Network121 (77.6%)
Unknown31 (19.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low122 (78.2%)
High3 (1.9%)
Unknown31 (19.9%)
User Interaction
None48 (30.8%)
Unknown31 (19.9%)
Required77 (49.4%)
Privileges Required
Low53 (34.0%)
High38 (24.4%)
None34 (21.8%)
Unknown31 (19.9%)
Top CVEs
Signals from CVEs in this product scope (156 CVEs).
156 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9053HIGH An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_i | Mar 26, 2019 | 8.1 | 74 | NO | YES |
CVE-2018-1000094HIGH CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to | Mar 13, 2018 | 7.2 | 65 | NO | YES |
CVE-2023-36969HIGH CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | Jul 6, 2023 | 8.8 | 59 | NO | YES |
CVE-2019-9692MEDIUM class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG). | Mar 11, 2019 | 6.5 | 59 | NO | YES |
CVE-2017-16783CRITICAL In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. | Nov 10, 2017 | 9.8 | 45 | NO | YES |
CVE-2018-7448HIGH Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" p | Feb 26, 2018 | 7.5 | 41 | NO | YES |
CVE-2007-5056MEDIUM Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open- | Sep 24, 2007 | 6.8 | 40 | NO | YES |
CVE-2018-10517HIGH In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because | Apr 27, 2018 | 7.2 | 39 | NO | YES |
CVE-2019-9055HIGH An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user | Mar 26, 2019 | 8.8 | 37 | NO | YES |
CVE-2017-8912HIGH CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunc | May 12, 2017 | 7.2 | 36 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (156 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
12.2% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (156 CVEs).
Media Mentions
Signals from CVEs in this product scope (156 CVEs).
Top CNAs Publishing CVEs For Cms Made Simple
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| beta_2 | 1 | 4.3 | 1.4% | 0 | 0 |
| beta_1 | 1 | 4.3 | 1.4% | 0 | 0 |
| 2.7 | 2 | 7.2 | 1.3% | 0 | 0 |
| 2.4_beta | 1 | 4.3 | 1.4% | 0 | 0 |
| 2.4 | 1 | 4.3 | 1.4% | 0 | 0 |
| 2.3 | 1 | 4.3 | 1.4% | 0 | 0 |
| 2.2.8 | 5 | 7.1 | 14.5% | 0 | 1 |
| 2.2.7 | 5 | 7.0 | 1.1% | 0 | 0 |
| 2.2.6 | 2 | 4.8 | 0.5% | 0 | 0 |
| 2.2.5 | 5 | 6.1 | 8.7% | 0 | 1 |
| 2.2.4 | 1 | 6.1 | 2.9% | 0 | 0 |
| 2.2.3.1 | 2 | 5.4 | 0.7% | 0 | 0 |
| 2.2.21 | 2 | 6.0 | 1.1% | 0 | 0 |
| 2.2.2 | 3 | 5.3 | 0.8% | 0 | 0 |
| 2.2.19 | 3 | 6.0 | 0.9% | 0 | 0 |
| 2.2.18 | 11 | 5.7 | 0.5% | 0 | 0 |
| 2.2.17 | 2 | 7.1 | 24.9% | 0 | 1 |
| 2.2.15 | 4 | 6.2 | 1.3% | 0 | 1 |
| 2.2.14 | 20 | 5.6 | 0.6% | 0 | 0 |
| 2.2.13 | 2 | 6.6 | 1.3% | 0 | 0 |