VendorsCodelyfestupid_simple_cmsall versions
Vulnerabilities

Codelyfe Stupid Simple CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-6901
codelyfe Stupid Simple CMS HTTP POST Request handle-command.php os command injection
Published 2023-12-17 · Modified
9.8EPSS 0.029
CVE-2023-6902
codelyfe Stupid Simple CMS upload.php unrestricted upload
Published 2023-12-17 · Modified
9.8EPSS 0.010
CVE-2023-6907
codelyfe Stupid Simple CMS Deletion Interface delete.php improper authentication
Published 2023-12-18 · Modified
9.1EPSS 0.012
CVE-2024-27689
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.
Published 2024-03-01 · Analyzed
8.8EPSS 0.003
CVE-2024-22715
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
Published 2024-01-17 · Modified
8.8EPSS 0.003
CVE-2023-7040
codelyfe Stupid Simple CMS rename.php path traversal
Published 2023-12-21 · Modified
6.5EPSS 0.008
CVE-2024-27559
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php
Published 2024-03-01 · Analyzed
6.3EPSS 0.002
CVE-2024-27558
Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
Published 2024-03-01 · Analyzed
6.1EPSS 0.004
CVE-2024-22714
Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.
Published 2024-01-17 · Modified
6.1EPSS 0.004
CVE-2024-3202
codelyfe Stupid Simple CMS Login Page excessive authentication
Published 2024-04-02 · Analyzed
5.9EPSS 0.012
CVE-2023-7041
codelyfe Stupid Simple CMS rename.php path traversal
Published 2023-12-21 · Modified
5.5EPSS 0.009