Simple PHP Scripts develops a narrow line of lightweight web applications, notably a blog and gallery platform, that emphasize ease of deployment for small-scale content sites. The recurring exposure centers on cross-site scripting vulnerabilities arising from improper input neutralization during HTML generation, a pattern characteristic of template-driven PHP applications where user-supplied data flows directly into page output without sufficient sanitization. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Php Scripts over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47918HIGH Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidat | Feb 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2021-47919MEDIUM Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request | Feb 1, 2026 | 6.4 | 21 | NO | NO |
CVE-2021-47917MEDIUM Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit | Feb 1, 2026 | 6.4 | 21 | NO | NO |
CVE-2023-3539MEDIUM A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php o | Jul 7, 2023 | 6.1 | 21 | NO | NO |
CVE-2008-4803MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery | Oct 31, 2008 | 4.3 | 21 | NO | YES |
CVE-2023-3476MEDIUM A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL | Jun 30, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-3475MEDIUM A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is some unknown functionality of the file preview.php of the co | Jun 30, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-3540MEDIUM A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the compo | Jul 7, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-3538MEDIUM A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL | Jul 7, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-3537MEDIUM A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an unknown part of the file /preview.php of the component URL Par | Jul 7, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Php Scripts.
Media articles that mention a CVE ID that affects a product developed by Simple Php Scripts — matched by CVE ID, not by vendor name.