VendorsCMS Made Simplecms_made_simple1.11.9
Vulnerabilities

CMS Made Simple CMS Made Simple 1.11.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-2784
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
Published 2016-05-26 · Modified
4.71 PoCEPSS 0.025
CVE-2013-3929
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.
Published 2013-12-09 · Modified
2.1EPSS 0.007