VendorsCMS Made Simplecms_made_simple2.2.10
Vulnerabilities

CMS Made Simple CMS Made Simple 2.2.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-11226
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
Published 2019-06-05 · Modified
5.4EPSS 0.009
CVE-2019-10017
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
Published 2019-03-24 · Modified
5.4EPSS 0.007
CVE-2019-10105
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.
Published 2019-03-26 · Modified
5.4EPSS 0.006
CVE-2019-10106
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.
Published 2019-03-26 · Modified
5.4EPSS 0.006
CVE-2019-10107
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
Published 2019-03-26 · Modified
5.4EPSS 0.006