Записи Get-Simple
47 опубликованных записей вендора get-simple.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 4,3 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')29
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
47 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2019-11231Готовый эксплойт | An issue was discovered in GetSimple CMS through 3.3.15.get-simple · getsimple cms · CWE-22 | Критическая9,8 | — | 71,6 % | 22 мая 2019 г. |
46В плане | CVE-2023-46042Эксплойта нет | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().get-simple · getsimplecms · CWE-94 | Критическая9,8 | — | 22,6 % | 19 окт. 2023 г. |
42В плане | CVE-2022-41544Proof of concept | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-ediget-simple · getsimple cms · CWE-94 | Критическая9,8 | — | 10,8 % | 18 окт. 2022 г. |
39Наблюдать | CVE-2023-6188Эксплойта нет | GetSimpleCMS theme-edit.php code injectionget-simple · getsimplecms · CWE-94 | Критическая9,8 | — | 1,0 % | 17 нояб. 2023 г. |
37Наблюдать | CVE-2020-18191Эксплойта нет | GetSimpleCMS-3.3.15 is affected by directory traversal.get-simple · getsimplecms · CWE-22 | Критическая9,1 | — | 2,1 % | 2 окт. 2020 г. |
35Наблюдать | CVE-2013-10032Готовый эксплойт | GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Uploadget-simple · getsimplecms · CWE-306 | Высокая8,7 | — | 3,7 % | 25 июл. 2025 г. |
35Наблюдать | CVE-2018-17103Эксплойта нет | An issue was discovered in GetSimple CMS v3.3.13.get-simple · getsimple cms · CWE-352 | Высокая8,8 | — | 0,7 % | 16 сент. 2018 г. |
34Наблюдать | CVE-2014-8722Proof of concept | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backuget-simple · getsimple cms · CWE-200 | Высокая7,5 | — | 14,4 % | 17 мар. 2017 г. |
34Наблюдать | CVE-2021-47778Эксплойта нет | GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injectionget-simple · getsimplecms · CWE-94 | Высокая8,6 | — | 1,3 % | 21 янв. 2026 г. |
34Наблюдать | CVE-2021-47860Эксплойта нет | GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCEget-simple · getsimplecms · CWE-352 | Высокая8,5 | — | 0,3 % | 21 янв. 2026 г. |
30Наблюдать | CVE-2021-28976Proof of concept | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.get-simple · getsimplecms · CWE-434 | Высокая7,2 | — | 7,5 % | 23 июн. 2021 г. |
27Наблюдать | CVE-2020-23839Proof of concept | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote atget-simple · getsimple cms · CWE-79 | Средняя6,1 | — | 10,5 % | 1 сент. 2020 г. |
27Наблюдать | CVE-2024-11125Эксплойта нет | GetSimpleCMS profile.php cross-site request forgeryget-simple · getsimplecms · CWE-352 | Средняя6,9 | — | 0,4 % | 12 нояб. 2024 г. |
25Наблюдать | CVE-2018-9173Proof of concept | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to injget-simple · getsimple cms · CWE-79 | Средняя6,1 | — | 2,4 % | 1 апр. 2018 г. |
24Наблюдать | CVE-2020-18658Эксплойта нет | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.get-simple · getsimplecms · CWE-79 | Средняя6,1 | — | 1,4 % | 23 июн. 2021 г. |
24Наблюдать | CVE-2020-18657Эксплойта нет | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_seget-simple · getsimplecms · CWE-79 | Средняя6,1 | — | 1,4 % | 23 июн. 2021 г. |
24Наблюдать | CVE-2020-18659Эксплойта нет | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.phpget-simple · getsimplecms · CWE-79 | Средняя6,1 | — | 1,3 % | 23 июн. 2021 г. |
24Наблюдать | CVE-2020-18660Эксплойта нет | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.get-simple · getsimplecms · CWE-601 | Средняя6,1 | — | 1,3 % | 23 июн. 2021 г. |
24Наблюдать | CVE-2013-1420Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or Hget-simple · getsimple cms · CWE-79 | Средняя6,1 | — | 1,1 % | 2 янв. 2020 г. |
24Наблюдать | CVE-2021-36601Эксплойта нет | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: get-simple · getsimplecms · CWE-79 | Средняя6,1 | — | 0,9 % | 10 авг. 2021 г. |
24Наблюдать | CVE-2018-16325Эксплойта нет | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.get-simple · getsimple cms · CWE-79 | Средняя6,1 | — | 0,8 % | 1 сент. 2018 г. |
24Наблюдать | CVE-2017-10673Эксплойта нет | admin/profile.php in GetSimple CMS 3.x has XSS in a name field.get-simple · getsimple cms · CWE-79 | Средняя6,1 | — | 0,7 % | 29 июн. 2017 г. |
21Наблюдать | CVE-2014-8790Эксплойта нет | XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configuracagintranetworks · getsimple cms | Средняя5,0 | — | 2,5 % | 20 янв. 2015 г. |
21Наблюдать | CVE-2014-8723Эксплойта нет | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plget-simple · getsimple cms · CWE-200 | Средняя5,3 | — | 1,2 % | 17 мар. 2017 г. |
21Наблюдать | CVE-2020-24861Эксплойта нет | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create get-simple · getsimple cms · CWE-79 | Средняя5,4 | — | 0,9 % | 1 окт. 2020 г. |
- CVE-2019-1123160На этой неделе
An issue was discovered in GetSimple CMS through 3.3.15.
КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %get-simple · getsimple cms22 мая 2019 г.
- CVE-2023-4604246В плане
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().
КритическаяCVSS 9,8Эксплойта нетEPSS 23 %get-simple · getsimplecms19 окт. 2023 г.
- CVE-2022-4154442В плане
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edi
КритическаяCVSS 9,8Proof of conceptEPSS 11 %get-simple · getsimple cms18 окт. 2022 г.
- CVE-2023-618839Наблюдать
GetSimpleCMS theme-edit.php code injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %get-simple · getsimplecms17 нояб. 2023 г.
- CVE-2020-1819137Наблюдать
GetSimpleCMS-3.3.15 is affected by directory traversal.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %get-simple · getsimplecms2 окт. 2020 г.
- CVE-2013-1003235Наблюдать
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
ВысокаяCVSS 8,7Готовый эксплойтEPSS 4 %get-simple · getsimplecms25 июл. 2025 г.
- CVE-2018-1710335Наблюдать
An issue was discovered in GetSimple CMS v3.3.13.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %get-simple · getsimple cms16 сент. 2018 г.
- CVE-2014-872234Наблюдать
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backu
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %get-simple · getsimple cms17 мар. 2017 г.
- CVE-2021-4777834Наблюдать
GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %get-simple · getsimplecms21 янв. 2026 г.
- CVE-2021-4786034Наблюдать
GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %get-simple · getsimplecms21 янв. 2026 г.
- CVE-2021-2897630Наблюдать
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
ВысокаяCVSS 7,2Proof of conceptEPSS 8 %get-simple · getsimplecms23 июн. 2021 г.
- CVE-2020-2383927Наблюдать
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote at
СредняяCVSS 6,1Proof of conceptEPSS 10 %get-simple · getsimple cms1 сент. 2020 г.
- CVE-2024-1112527Наблюдать
GetSimpleCMS profile.php cross-site request forgery
СредняяCVSS 6,9Эксплойта нетEPSS 0 %get-simple · getsimplecms12 нояб. 2024 г.
- CVE-2018-917325Наблюдать
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inj
СредняяCVSS 6,1Proof of conceptEPSS 2 %get-simple · getsimple cms1 апр. 2018 г.
- CVE-2020-1865824Наблюдать
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimplecms23 июн. 2021 г.
- CVE-2020-1865724Наблюдать
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_se
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimplecms23 июн. 2021 г.
- CVE-2020-1865924Наблюдать
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimplecms23 июн. 2021 г.
- CVE-2020-1866024Наблюдать
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimplecms23 июн. 2021 г.
- CVE-2013-142024Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or H
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimple cms2 янв. 2020 г.
- CVE-2021-3660124Наблюдать
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL:
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimplecms10 авг. 2021 г.
- CVE-2018-1632524Наблюдать
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimple cms1 сент. 2018 г.
- CVE-2017-1067324Наблюдать
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %get-simple · getsimple cms29 июн. 2017 г.
- CVE-2014-879021Наблюдать
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configura
СредняяCVSS 5,0Эксплойта нетEPSS 3 %cagintranetworks · getsimple cms20 янв. 2015 г.
- CVE-2014-872321Наблюдать
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) pl
СредняяCVSS 5,3Эксплойта нетEPSS 1 %get-simple · getsimple cms17 мар. 2017 г.
- CVE-2020-2486121Наблюдать
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create
СредняяCVSS 5,4Эксплойта нетEPSS 1 %get-simple · getsimple cms1 окт. 2020 г.