VendorsCMS Made Simplecms_made_simple2.2.19
Vulnerabilities

CMS Made Simple CMS Made Simple 2.2.19

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-27622
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
Published 2024-03-05 · Analyzed
7.2EPSS 0.020
CVE-2024-27623
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
Published 2024-03-05 · Modified
5.9EPSS 0.004
CVE-2024-27625
CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field.
Published 2024-03-05 · Analyzed
4.8EPSS 0.004