VendorsCagintranetworksgetsimple_cmsall versions
Vulnerabilities

Cagintranetworks Cagintranet Networks GetSimple CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-8081
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.
Published 2017-04-30 · Modified
8.8EPSS 0.013
CVE-2014-8790
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
Published 2015-01-20 · Modified
5.0EPSS 0.025