Перейти к содержимому
Noroxi

Записи Get-Simple

47 опубликованных записей вендора get-simple.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
2 · 4,3 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

47 записей
  • CVE-2019-11231
    60На этой неделе

    An issue was discovered in GetSimple CMS through 3.3.15.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %

    get-simple · getsimple cms22 мая 2019 г.

  • CVE-2023-46042
    46В плане

    An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().

    КритическаяCVSS 9,8Эксплойта нетEPSS 23 %

    get-simple · getsimplecms19 окт. 2023 г.

  • CVE-2022-41544
    42В плане

    GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edi

    КритическаяCVSS 9,8Proof of conceptEPSS 11 %

    get-simple · getsimple cms18 окт. 2022 г.

  • CVE-2023-6188
    39Наблюдать

    GetSimpleCMS theme-edit.php code injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    get-simple · getsimplecms17 нояб. 2023 г.

  • CVE-2020-18191
    37Наблюдать

    GetSimpleCMS-3.3.15 is affected by directory traversal.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    get-simple · getsimplecms2 окт. 2020 г.

  • CVE-2013-10032
    35Наблюдать

    GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload

    ВысокаяCVSS 8,7Готовый эксплойтEPSS 4 %

    get-simple · getsimplecms25 июл. 2025 г.

  • CVE-2018-17103
    35Наблюдать

    An issue was discovered in GetSimple CMS v3.3.13.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    get-simple · getsimple cms16 сент. 2018 г.

  • CVE-2014-8722
    34Наблюдать

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backu

    ВысокаяCVSS 7,5Proof of conceptEPSS 14 %

    get-simple · getsimple cms17 мар. 2017 г.

  • CVE-2021-47778
    34Наблюдать

    GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    get-simple · getsimplecms21 янв. 2026 г.

  • CVE-2021-47860
    34Наблюдать

    GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    get-simple · getsimplecms21 янв. 2026 г.

  • CVE-2021-28976
    30Наблюдать

    Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.

    ВысокаяCVSS 7,2Proof of conceptEPSS 8 %

    get-simple · getsimplecms23 июн. 2021 г.

  • CVE-2020-23839
    27Наблюдать

    A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote at

    СредняяCVSS 6,1Proof of conceptEPSS 10 %

    get-simple · getsimple cms1 сент. 2020 г.

  • CVE-2024-11125
    27Наблюдать

    GetSimpleCMS profile.php cross-site request forgery

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    get-simple · getsimplecms12 нояб. 2024 г.

  • CVE-2018-9173
    25Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inj

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    get-simple · getsimple cms1 апр. 2018 г.

  • CVE-2020-18658
    24Наблюдать

    Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimplecms23 июн. 2021 г.

  • CVE-2020-18657
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_se

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimplecms23 июн. 2021 г.

  • CVE-2020-18659
    24Наблюдать

    Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimplecms23 июн. 2021 г.

  • CVE-2020-18660
    24Наблюдать

    GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimplecms23 июн. 2021 г.

  • CVE-2013-1420
    24Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or H

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimple cms2 янв. 2020 г.

  • CVE-2021-36601
    24Наблюдать

    GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL:

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimplecms10 авг. 2021 г.

  • CVE-2018-16325
    24Наблюдать

    There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimple cms1 сент. 2018 г.

  • CVE-2017-10673
    24Наблюдать

    admin/profile.php in GetSimple CMS 3.x has XSS in a name field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    get-simple · getsimple cms29 июн. 2017 г.

  • CVE-2014-8790
    21Наблюдать

    XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configura

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    cagintranetworks · getsimple cms20 янв. 2015 г.

  • CVE-2014-8723
    21Наблюдать

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) pl

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    get-simple · getsimple cms17 мар. 2017 г.

  • CVE-2020-24861
    21Наблюдать

    GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    get-simple · getsimple cms1 окт. 2020 г.