Filtered by vendor Cmsmadesimple Subscriptions
Filtered by product Cms Made Simple Subscriptions
Total 147 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-6072 1 Cmsmadesimple 2 Cms Made Simple, Form Builder 2024-08-05 N/A
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
CVE-2017-6071 1 Cmsmadesimple 2 Cms Made Simple, Form Builder 2024-08-05 5.3 Medium
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
CVE-2017-6070 1 Cmsmadesimple 2 Cms Made Simple, Form Builder 2024-08-05 N/A
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.
CVE-2018-1000158 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Reset Poisoning, specifically a reset URL pointing at an attacker controlled server can be created by using a host header attack.
CVE-2018-1000092 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.
CVE-2018-1000094 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.
CVE-2018-20464 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
CVE-2018-19597 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
CVE-2018-10517 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.
CVE-2018-9921 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
CVE-2018-8058 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
CVE-2018-7893 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
CVE-2018-7448 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
CVE-2018-5963 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.
CVE-2018-5964 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.
CVE-2018-5965 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 N/A
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
CVE-2019-17630 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 4.8 Medium
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
CVE-2019-17629 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 4.8 Medium
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
CVE-2019-17226 1 Cmsmadesimple 1 Cms Made Simple 2024-08-05 4.8 Medium
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
CVE-2019-11513 1 Cmsmadesimple 1 Cms Made Simple 2024-08-04 N/A
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.