Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.69%—Cmsmadesimple CMS Made Simple28/5/202017/6/2026
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
ModificadaAlta (7.8)2.0%—Cmsmadesimple CMS Made Simple20/3/202017/6/2026
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).
ModificadaMedia (5.4)0.62%—Cmsmadesimple CMS Made Simple20/3/202017/6/2026
The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.
ModificadaAlta (7.5)1.1%—Cmsmadesimple CMS Made Simple26/11/201916/6/2026
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
ModificadaMedia (4.8)0.54%—Cmsmadesimple CMS Made Simple16/10/201917/6/2026
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
ModificadaMedia (4.8)0.54%—Cmsmadesimple CMS Made Simple16/10/201917/6/2026
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
ModificadaMedia (4.8)0.58%—Cmsmadesimple CMS Made Simple6/10/201917/6/2026
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
ModificadaMedia (5.4)0.90%—Cmsmadesimple CMS Made Simple5/6/201917/6/2026
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
ModificadaMedia (4.8)0.60%—Cmsmadesimple CMS Made Simple25/4/201917/6/2026
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
ModificadaAlta (8.8)1.3%—Cmsmadesimple CMS Made Simple11/4/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.
ModificadaMedia (5.4)0.64%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
ModificadaMedia (5.4)0.64%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.
ModificadaMedia (5.4)0.64%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.
ModificadaAlta (8.8)1.6%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.
ModificadaAlta (7.2)1.8%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password" feature.
ModificadaAlta (7.2)1.2%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.
ModificadaAlta (8.8)1.6%—Cmsmadesimple CMS Made Simple26/3/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.
ModificadaAlta (8.8)12%💥 ExploitCmsmadesimple CMS Made Simple26/3/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object…
ModificadaAlta (8.1)69%💥 ExploitCmsmadesimple CMS Made Simple26/3/201917/6/2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
ModificadaMedia (5.4)0.66%—Cmsmadesimple CMS Made Simple24/3/201917/6/2026
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
ModificadaAlta (8.8)1.2%—Cmsmadesimple CMS Made Simple11/3/201917/6/2026
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber),…
ModificadaMedia (6.5)46%💥 ExploitCmsmadesimple CMS Made Simple11/3/201917/6/2026
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
ModificadaMedia (6.1)0.68%—Cmsmadesimple CMS Made Simple25/12/201817/6/2026
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
ModificadaMedia (4.8)0.67%—Cmsmadesimple CMS Made Simple19/12/201817/6/2026
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
ModificadaMedia (6.1)0.83%—Cmsmadesimple CMS Made Simple12/10/201817/6/2026
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
Orbitaley — Vulnerabilidades