CVE-2024-57546
- EPSS 0.57%
- Veröffentlicht 27.01.2025 23:15:09
- Zuletzt bearbeitet 16.04.2025 15:14:58
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.
CVE-2024-33423
- EPSS 0.56%
- Veröffentlicht 01.05.2024 20:15:12
- Zuletzt bearbeitet 14.04.2025 14:22:00
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language section.
CVE-2024-33424
- EPSS 0.4%
- Veröffentlicht 01.05.2024 19:15:27
- Zuletzt bearbeitet 14.04.2025 14:21:50
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Downloads parameter under the Language section.
CVE-2024-32392
- EPSS 0.77%
- Veröffentlicht 19.04.2024 21:15:08
- Zuletzt bearbeitet 14.04.2025 13:49:29
Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.
CVE-2024-32345
- EPSS 0.46%
- Veröffentlicht 17.04.2024 21:15:09
- Zuletzt bearbeitet 11.04.2025 14:49:51
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Configuration parameter under the Language section.
CVE-2024-32344
- EPSS 0.53%
- Veröffentlicht 17.04.2024 21:15:09
- Zuletzt bearbeitet 11.04.2025 14:50:02
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under the Language section.
CVE-2021-43741
- EPSS 4.42%
- Veröffentlicht 13.04.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:41
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
CVE-2021-43742
- EPSS 0.56%
- Veröffentlicht 13.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:41
CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.
CVE-2018-19508
- EPSS 0.56%
- Veröffentlicht 19.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:03
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.
CVE-2018-19507
- EPSS 0.56%
- Veröffentlicht 19.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:03
CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.