Vulnerabilities
23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-47736 | CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server. NVD description · AI analysis pending | 8.6 | 1% | PoC |
| — | |
| CVE-2021-47735 | CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token. NVD description · AI analysis pending | 8.6 group max | <1% | PoC |
| — | |
| CVE-2024-58280 | CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server. NVD description · AI analysis pending | 8.6 | <1% | PoC |
| — | |
| CVE-2025-63588 +1 in the same advisory: …63589 | An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary Java An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2024-57548 | CMSimple 5.16 allows the user to edit log.php file via print page. CMSimple 5.16 allows the user to edit log.php file via print page. NVD description · AI analysis pending | 9.1 group max | <1% | PoC |
| — | |
| CVE-2024-34452 | CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document. CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2024-33423 +1 in the same advisory: …33424 | Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language section. NVD description · AI analysis pending | 7.4 group max | <1% | PoC |
| — | |
| CVE-2024-32392 | Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component. Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component. NVD description · AI analysis pending | 4.5 | <1% | PoC |
| — | |
| CVE-2024-32345 +1 in the same advisory: …32344 | A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Configuration parameter under the Language section. NVD description · AI analysis pending | 7.2 group max | <1% | PoC |
| — | |
| CVE-2021-42645 | CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host. NVD description · AI analysis pending | 10.0 | 5% | PoC |
| — | |
| CVE-2021-43741 +1 in the same advisory: …43742 | CMSimple 5.4 is vulnerable to Directory Traversal. CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution. NVD description · AI analysis pending | 9.8 group max | 5% | PoC |
| — | |
| CVE-2018-19508 +1 in the same advisory: …19507 | CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI. CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — |