Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Getsimple_cms
(Get\-Simple)Repositories | https://github.com/GetSimpleCMS/GetSimpleCMS |
#Vulnerabilities | 26 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2018-04-02 | CVE-2018-9173 | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter. | Getsimple_cms | 6.1 | ||
2018-12-31 | CVE-2018-19845 | There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325. | Getsimple_cms | 5.4 | ||
2018-11-21 | CVE-2018-19421 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php. | Getsimple_cms | 3.8 | ||
2018-11-21 | CVE-2018-19420 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php. | Getsimple_cms | 3.8 | ||
2018-10-01 | CVE-2018-17835 | An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI. | Getsimple_cms | 4.8 | ||
2018-09-01 | CVE-2018-16325 | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field. | Getsimple_cms | 6.1 | ||
2018-08-25 | CVE-2018-15843 | GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field. | Getsimple_cms | 4.8 | ||
2015-07-01 | CVE-2015-5356 | Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter. | Getsimple_cms | N/A | ||
2015-07-01 | CVE-2015-5355 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php. | Getsimple_cms | N/A | ||
2015-01-20 | CVE-2014-8790 | XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter. | Getsimple_cms, Getsimple_cms | N/A |