« Volver al listado

Cmsimple-xh

Cmsimple-xh Cmsimple XH: vulnerabilidades y CVE

Cmsimple-xh Cmsimple XH tiene 5 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses3
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-47736Alta (8.6)1.1%—23 dic 2025
CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can…
CVE-2025-63589Alta (7.1)0.33%—6 nov 2025
A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links,…
CVE-2025-63588Alta (7.1)0.34%—6 nov 2025
An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a…
CVE-2024-34452Media (6.1)0.71%—21 jun 2024
CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.
CVE-2021-42645Crítica (10)4.8%—10 may 2022
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1189 Drive-by Compromise2
  3. T1059 Command and Scripting Interpreter1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.