CVE-2024-33424
- EPSS 0.21%
- Veröffentlicht 01.05.2024 19:15:27
- Zuletzt bearbeitet 14.04.2025 14:21:50
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Downloads parameter under the Language section.
CVE-2024-32392
- EPSS 0.22%
- Veröffentlicht 19.04.2024 21:15:08
- Zuletzt bearbeitet 14.04.2025 13:49:29
Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.
CVE-2024-32345
- EPSS 0.13%
- Veröffentlicht 17.04.2024 21:15:09
- Zuletzt bearbeitet 11.04.2025 14:49:51
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Configuration parameter under the Language section.
CVE-2024-32344
- EPSS 0.1%
- Veröffentlicht 17.04.2024 21:15:09
- Zuletzt bearbeitet 11.04.2025 14:50:02
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under the Language section.
CVE-2021-43741
- EPSS 11.36%
- Veröffentlicht 13.04.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:41
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
CVE-2021-43742
- EPSS 0.21%
- Veröffentlicht 13.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:41
CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.
CVE-2018-19508
- EPSS 0.24%
- Veröffentlicht 19.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:03
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.
CVE-2018-19507
- EPSS 0.24%
- Veröffentlicht 19.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:03
CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.
CVE-2008-2650
- EPSS 1.88%
- Veröffentlicht 10.06.2008 18:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leve...