Simplece maintains a focused web application product that exhibits recurring vulnerabilities centered on client-side interaction and request handling, specifically cross-site request forgery and cross-site scripting flaws. These weakness classes reflect input-validation and state-management challenges common to web-facing platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplece over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9673HIGH In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), inc | Jun 15, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-9674MEDIUM In SimpleCE 2.3.0, an authenticated XSS vulnerability was found on index.php/content/text/1?return_url=[XSS] exploitable as a regular or admin user. | Jun 15, 2017 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplece.
Media articles that mention a CVE ID that affects a product developed by Simplece — matched by CVE ID, not by vendor name.