Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-17735 |
|
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
|
| CVE-2017-17734 |
|
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
|
| CVE-2017-16799 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-16799)
cross-site scripting in cmsmadesimple (CVE-2017-16799). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-16798 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-16798)
cross-site scripting in cmsmadesimple (CVE-2017-16798). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-16784 |
|
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
|
| CVE-2017-16783 |
|
Code Injection in cmsmadesimple (CVE-2017-16783)
code injection in cmsmadesimple (CVE-2017-16783). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11405 |
|
Unrestricted File Upload in cmsmadesimple (CVE-2017-11405)
vulnerability in cmsmadesimple (CVE-2017-11405). Data can be tampered with by attackers.
|
| CVE-2017-11404 |
|
Unrestricted File Upload in cmsmadesimple (CVE-2017-11404)
vulnerability in cmsmadesimple (CVE-2017-11404). Data can be tampered with by attackers.
|
| CVE-2017-9668 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-9668)
cross-site scripting in cmsmadesimple (CVE-2017-9668). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8912 |
|
Code Injection in cmsmadesimple (CVE-2017-8912)
code injection in cmsmadesimple (CVE-2017-8912). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7257 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-7257)
cross-site scripting in cmsmadesimple (CVE-2017-7257). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-7256 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-7256)
cross-site scripting in cmsmadesimple (CVE-2017-7256). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-7255 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-7255)
cross-site scripting in cmsmadesimple (CVE-2017-7255). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6556 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-6556)
cross-site scripting in cmsmadesimple (CVE-2017-6556). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6555 |
|
Cross-Site Scripting (XSS) in cmsmadesimple (CVE-2017-6555)
cross-site scripting in cmsmadesimple (CVE-2017-6555). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6072 |
|
Information Disclosure in cmsmadesimple (CVE-2017-6072)
vulnerability in cmsmadesimple (CVE-2017-6072). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6071 |
|
Information Disclosure in cmsmadesimple (CVE-2017-6071)
vulnerability in cmsmadesimple (CVE-2017-6071). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6070 |
|
Information Disclosure in cmsmadesimple (CVE-2017-6070)
vulnerability in cmsmadesimple (CVE-2017-6070). Successful exploitation can lead to full system takeover.
|
| CVE-2016-7904 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2016-7904)
vulnerability in csrf (CVE-2016-7904). Successful exploitation can lead to full system takeover.
|