Cmsimple
Cmsimple: vulnerabilidades y CVE
Cmsimple tiene 21 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses7
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88418 | Alta (8.8) | 0.25% | — | 22 sept 2026 | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because… |
| CVE-2026-78834 | Alta (8.8) | 0.67% | — | 8 sept 2026 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution… |
| CVE-2021-47735 | Alta (8.6) | 0.88% | — | 23 dic 2025 | CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by… |
| CVE-2021-47734 | Alta (8.6) | 0.78% | — | 23 dic 2025 | CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the… |
| CVE-2021-47733 | Media (5.1) | 0.26% | — | 23 dic 2025 | CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts by encoding payloads like… |
| CVE-2021-47732 | Media (5.1) | 0.27% | — | 23 dic 2025 | CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that… |
| CVE-2024-58280 | Alta (8.6) | 0.94% | — | 10 dic 2025 | CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and… |
| CVE-2024-57549 | Alta (7.5) | 0.66% | — | 27 ene 2025 | CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request. |
| CVE-2024-57548 | Crítica (9.1) | 0.47% | — | 27 ene 2025 | CMSimple 5.16 allows the user to edit log.php file via print page. |
| CVE-2024-57547 | Alta (7.5) | 0.56% | — | 27 ene 2025 | Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files. |
| CVE-2024-57546 | Alta (7.5) | 0.58% | — | 27 ene 2025 | An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function. |
| CVE-2024-33423 | Alta (7.4) | 0.56% | — | 1 may 2024 | Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language… |
| CVE-2024-33424 | Media (6.1) | 0.40% | — | 1 may 2024 | A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Downloads parameter under the Language… |
| CVE-2024-32392 | Media (4.5) | 0.77% | — | 19 abr 2024 | Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component. |
| CVE-2024-32345 | Alta (7.2) | 0.46% | — | 17 abr 2024 | A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Configuration parameter under the… |
| CVE-2024-32344 | Media (6.8) | 0.53% | — | 17 abr 2024 | A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under the Language… |
| CVE-2021-43741 | Crítica (9.8) | 4.7% | — | 13 abr 2022 | CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution. |
| CVE-2021-43742 | Media (5.4) | 0.57% | — | 13 abr 2022 | CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature. |
| CVE-2018-19508 | Media (4.8) | 0.56% | — | 19 dic 2018 | CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI. |
| CVE-2018-19507 | Media (4.8) | 0.56% | — | 19 dic 2018 | CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI. |
| CVE-2008-2650 | Media (6.8) | 19% | — | 10 jun 2008 | Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.