Filtered by vendor Cmsmadesimple Subscriptions
Filtered by product Cms Made Simple Subscriptions
Total 153 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-6071 1 Cmsmadesimple 2 Cms Made Simple, Form Builder 2024-11-21 5.3 Medium
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
CVE-2017-6070 1 Cmsmadesimple 2 Cms Made Simple, Form Builder 2024-11-21 N/A
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.
CVE-2017-17735 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
CVE-2017-17734 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
CVE-2017-16798 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 5.4 Medium
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.
CVE-2017-16784 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
CVE-2017-16783 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 9.8 Critical
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
CVE-2017-11405 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.
CVE-2017-11404 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
CVE-2017-1000454 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
CVE-2017-1000453 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
CVE-2016-7904 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.
CVE-2011-4310 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 7.5 High
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.