Codelyfe's vulnerability profile centers on Stupid Simple CMS, a modestly represented content-management platform, where disclosures cluster around input-handling and authentication weaknesses endemic to web applications. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including cross-site request forgery, cross-site scripting, path traversal, improper authentication, and OS command injection, reflecting the validation and access-control demands of publicly exposed CMS engines. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codelyfe over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6901CRITICAL A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an unknown part of the file /terminal/handle-command.php of the | Dec 17, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-6902CRITICAL A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. T | Dec 17, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-27689HIGH Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php. | Mar 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-22715HIGH Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php. | Jan 17, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-6907CRITICAL A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /file-ma | Dec 18, 2023 | 9.1 | 22 | NO | NO |
CVE-2023-7040MEDIUM A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/ | Dec 21, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-3202MEDIUM A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. Th | Apr 2, 2024 | 5.9 | 18 | NO | NO |
CVE-2024-27559MEDIUM Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php | Mar 1, 2024 | 6.3 | 18 | NO | NO |
CVE-2024-27558MEDIUM Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings. | Mar 1, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-22714MEDIUM Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content. | Jan 17, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codelyfe.
Media articles that mention a CVE ID that affects a product developed by Codelyfe — matched by CVE ID, not by vendor name.