VendorsCMS Made Simplecms_made_simple2.2.14
Vulnerabilities

CMS Made Simple CMS Made Simple 2.2.14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2024-1527
Unrestricted Upload of File with Dangerous Type in CMS Made Simple
Published 2024-03-12 · Analyzed
9.8EPSS 0.009
CVE-2020-17462
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
Published 2020-08-14 · Modified
7.8EPSS 0.010
CVE-2024-1529
Cross-site Scripting in CMS Made Simple
Published 2024-03-12 · Analyzed
7.4EPSS 0.004
CVE-2024-1528
Cross-site Scripting in CMS Made Simple
Published 2024-03-12 · Analyzed
7.4EPSS 0.004
CVE-2020-24860
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
Published 2020-10-01 · Modified
5.4EPSS 0.011
CVE-2020-14926
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
Published 2020-06-19 · Modified
5.4EPSS 0.006
CVE-2020-23481
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
Published 2021-09-22 · Modified
5.4EPSS 0.005
CVE-2020-36408
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Shortcut" parameter under the "Manage Shortcuts" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36409
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Category" parameter under the "Categories" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36410
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter under the "Options" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36411
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Path for the {page_image} tag:" or "Path for thumbnail field:" parameters under the "Content Editing Settings" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36412
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36413
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "Site Down" status" parameter under the "Maintenance Mode" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36414
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "URL (slug)" or "Extra" fields under the "Add Article" feature.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36415
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Stylesheet" parameter under the "Stylesheets" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-36416
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.
Published 2021-07-02 · Modified
5.4EPSS 0.005
CVE-2020-27377
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
Published 2021-06-01 · Modified
4.8EPSS 0.005
CVE-2020-22732
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
Published 2021-08-05 · Modified
4.8EPSS 0.005
CVE-2020-23241
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
Published 2021-07-26 · Modified
4.8EPSS 0.005
CVE-2020-23240
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
Published 2021-07-26 · Modified
4.8EPSS 0.005