Get-Simple kayıtları
get-simple üreticisine ait 47 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %4,3
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')29
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
47 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2019-11231Silahlaştırılmış | An issue was discovered in GetSimple CMS through 3.3.15.get-simple · getsimple cms · CWE-22 | Kritik9,8 | — | %71,6 | 22 May 2019 |
46Planlayın | CVE-2023-46042İstismar yok | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().get-simple · getsimplecms · CWE-94 | Kritik9,8 | — | %22,6 | 19 Eki 2023 |
42Planlayın | CVE-2022-41544Kavram kanıtı | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-ediget-simple · getsimple cms · CWE-94 | Kritik9,8 | — | %10,8 | 18 Eki 2022 |
39İzleyin | CVE-2023-6188İstismar yok | GetSimpleCMS theme-edit.php code injectionget-simple · getsimplecms · CWE-94 | Kritik9,8 | — | %1,0 | 17 Kas 2023 |
37İzleyin | CVE-2020-18191İstismar yok | GetSimpleCMS-3.3.15 is affected by directory traversal.get-simple · getsimplecms · CWE-22 | Kritik9,1 | — | %2,1 | 2 Eki 2020 |
35İzleyin | CVE-2013-10032Silahlaştırılmış | GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Uploadget-simple · getsimplecms · CWE-306 | Yüksek8,7 | — | %3,7 | 25 Tem 2025 |
35İzleyin | CVE-2018-17103İstismar yok | An issue was discovered in GetSimple CMS v3.3.13.get-simple · getsimple cms · CWE-352 | Yüksek8,8 | — | %0,7 | 16 Eyl 2018 |
34İzleyin | CVE-2014-8722Kavram kanıtı | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backuget-simple · getsimple cms · CWE-200 | Yüksek7,5 | — | %14,4 | 17 Mar 2017 |
34İzleyin | CVE-2021-47778İstismar yok | GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injectionget-simple · getsimplecms · CWE-94 | Yüksek8,6 | — | %1,3 | 21 Oca 2026 |
34İzleyin | CVE-2021-47860İstismar yok | GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCEget-simple · getsimplecms · CWE-352 | Yüksek8,5 | — | %0,3 | 21 Oca 2026 |
30İzleyin | CVE-2021-28976Kavram kanıtı | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.get-simple · getsimplecms · CWE-434 | Yüksek7,2 | — | %7,5 | 23 Haz 2021 |
27İzleyin | CVE-2020-23839Kavram kanıtı | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote atget-simple · getsimple cms · CWE-79 | Orta6,1 | — | %10,5 | 1 Eyl 2020 |
27İzleyin | CVE-2024-11125İstismar yok | GetSimpleCMS profile.php cross-site request forgeryget-simple · getsimplecms · CWE-352 | Orta6,9 | — | %0,4 | 12 Kas 2024 |
25İzleyin | CVE-2018-9173Kavram kanıtı | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to injget-simple · getsimple cms · CWE-79 | Orta6,1 | — | %2,4 | 1 Nis 2018 |
24İzleyin | CVE-2020-18658İstismar yok | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.get-simple · getsimplecms · CWE-79 | Orta6,1 | — | %1,4 | 23 Haz 2021 |
24İzleyin | CVE-2020-18657İstismar yok | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_seget-simple · getsimplecms · CWE-79 | Orta6,1 | — | %1,4 | 23 Haz 2021 |
24İzleyin | CVE-2020-18659İstismar yok | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.phpget-simple · getsimplecms · CWE-79 | Orta6,1 | — | %1,3 | 23 Haz 2021 |
24İzleyin | CVE-2020-18660İstismar yok | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.get-simple · getsimplecms · CWE-601 | Orta6,1 | — | %1,3 | 23 Haz 2021 |
24İzleyin | CVE-2013-1420İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or Hget-simple · getsimple cms · CWE-79 | Orta6,1 | — | %1,1 | 2 Oca 2020 |
24İzleyin | CVE-2021-36601İstismar yok | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: get-simple · getsimplecms · CWE-79 | Orta6,1 | — | %0,9 | 10 Ağu 2021 |
24İzleyin | CVE-2018-16325İstismar yok | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.get-simple · getsimple cms · CWE-79 | Orta6,1 | — | %0,8 | 1 Eyl 2018 |
24İzleyin | CVE-2017-10673İstismar yok | admin/profile.php in GetSimple CMS 3.x has XSS in a name field.get-simple · getsimple cms · CWE-79 | Orta6,1 | — | %0,7 | 29 Haz 2017 |
21İzleyin | CVE-2014-8790İstismar yok | XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configuracagintranetworks · getsimple cms | Orta5,0 | — | %2,5 | 20 Oca 2015 |
21İzleyin | CVE-2014-8723İstismar yok | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plget-simple · getsimple cms · CWE-200 | Orta5,3 | — | %1,2 | 17 Mar 2017 |
21İzleyin | CVE-2020-24861İstismar yok | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create get-simple · getsimple cms · CWE-79 | Orta5,4 | — | %0,9 | 1 Eki 2020 |
- CVE-2019-1123160Bu hafta
An issue was discovered in GetSimple CMS through 3.3.15.
KritikCVSS 9,8SilahlaştırılmışEPSS %72get-simple · getsimple cms22 May 2019
- CVE-2023-4604246Planlayın
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().
KritikCVSS 9,8İstismar yokEPSS %23get-simple · getsimplecms19 Eki 2023
- CVE-2022-4154442Planlayın
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edi
KritikCVSS 9,8Kavram kanıtıEPSS %11get-simple · getsimple cms18 Eki 2022
- CVE-2023-618839İzleyin
GetSimpleCMS theme-edit.php code injection
KritikCVSS 9,8İstismar yokEPSS %1get-simple · getsimplecms17 Kas 2023
- CVE-2020-1819137İzleyin
GetSimpleCMS-3.3.15 is affected by directory traversal.
KritikCVSS 9,1İstismar yokEPSS %2get-simple · getsimplecms2 Eki 2020
- CVE-2013-1003235İzleyin
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
YüksekCVSS 8,7SilahlaştırılmışEPSS %4get-simple · getsimplecms25 Tem 2025
- CVE-2018-1710335İzleyin
An issue was discovered in GetSimple CMS v3.3.13.
YüksekCVSS 8,8İstismar yokEPSS %1get-simple · getsimple cms16 Eyl 2018
- CVE-2014-872234İzleyin
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backu
YüksekCVSS 7,5Kavram kanıtıEPSS %14get-simple · getsimple cms17 Mar 2017
- CVE-2021-4777834İzleyin
GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
YüksekCVSS 8,6İstismar yokEPSS %1get-simple · getsimplecms21 Oca 2026
- CVE-2021-4786034İzleyin
GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
YüksekCVSS 8,5İstismar yokEPSS %0get-simple · getsimplecms21 Oca 2026
- CVE-2021-2897630İzleyin
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
YüksekCVSS 7,2Kavram kanıtıEPSS %8get-simple · getsimplecms23 Haz 2021
- CVE-2020-2383927İzleyin
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote at
OrtaCVSS 6,1Kavram kanıtıEPSS %10get-simple · getsimple cms1 Eyl 2020
- CVE-2024-1112527İzleyin
GetSimpleCMS profile.php cross-site request forgery
OrtaCVSS 6,9İstismar yokEPSS %0get-simple · getsimplecms12 Kas 2024
- CVE-2018-917325İzleyin
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inj
OrtaCVSS 6,1Kavram kanıtıEPSS %2get-simple · getsimple cms1 Nis 2018
- CVE-2020-1865824İzleyin
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimplecms23 Haz 2021
- CVE-2020-1865724İzleyin
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_se
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimplecms23 Haz 2021
- CVE-2020-1865924İzleyin
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimplecms23 Haz 2021
- CVE-2020-1866024İzleyin
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimplecms23 Haz 2021
- CVE-2013-142024İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or H
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimple cms2 Oca 2020
- CVE-2021-3660124İzleyin
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL:
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimplecms10 Ağu 2021
- CVE-2018-1632524İzleyin
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimple cms1 Eyl 2018
- CVE-2017-1067324İzleyin
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
OrtaCVSS 6,1İstismar yokEPSS %1get-simple · getsimple cms29 Haz 2017
- CVE-2014-879021İzleyin
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configura
OrtaCVSS 5,0İstismar yokEPSS %3cagintranetworks · getsimple cms20 Oca 2015
- CVE-2014-872321İzleyin
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) pl
OrtaCVSS 5,3İstismar yokEPSS %1get-simple · getsimple cms17 Mar 2017
- CVE-2020-2486121İzleyin
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create
OrtaCVSS 5,4İstismar yokEPSS %1get-simple · getsimple cms1 Eki 2020