İçeriğe atla
Noroxi

Get-Simple kayıtları

get-simple üreticisine ait 47 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %4,3
Pre-auth RCE
5
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

47 kayıt
  • CVE-2019-11231
    60Bu hafta

    An issue was discovered in GetSimple CMS through 3.3.15.

    KritikCVSS 9,8SilahlaştırılmışEPSS %72

    get-simple · getsimple cms22 May 2019

  • CVE-2023-46042
    46Planlayın

    An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().

    KritikCVSS 9,8İstismar yokEPSS %23

    get-simple · getsimplecms19 Eki 2023

  • CVE-2022-41544
    42Planlayın

    GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edi

    KritikCVSS 9,8Kavram kanıtıEPSS %11

    get-simple · getsimple cms18 Eki 2022

  • CVE-2023-6188
    39İzleyin

    GetSimpleCMS theme-edit.php code injection

    KritikCVSS 9,8İstismar yokEPSS %1

    get-simple · getsimplecms17 Kas 2023

  • CVE-2020-18191
    37İzleyin

    GetSimpleCMS-3.3.15 is affected by directory traversal.

    KritikCVSS 9,1İstismar yokEPSS %2

    get-simple · getsimplecms2 Eki 2020

  • CVE-2013-10032
    35İzleyin

    GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload

    YüksekCVSS 8,7SilahlaştırılmışEPSS %4

    get-simple · getsimplecms25 Tem 2025

  • CVE-2018-17103
    35İzleyin

    An issue was discovered in GetSimple CMS v3.3.13.

    YüksekCVSS 8,8İstismar yokEPSS %1

    get-simple · getsimple cms16 Eyl 2018

  • CVE-2014-8722
    34İzleyin

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backu

    YüksekCVSS 7,5Kavram kanıtıEPSS %14

    get-simple · getsimple cms17 Mar 2017

  • CVE-2021-47778
    34İzleyin

    GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection

    YüksekCVSS 8,6İstismar yokEPSS %1

    get-simple · getsimplecms21 Oca 2026

  • CVE-2021-47860
    34İzleyin

    GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE

    YüksekCVSS 8,5İstismar yokEPSS %0

    get-simple · getsimplecms21 Oca 2026

  • CVE-2021-28976
    30İzleyin

    Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.

    YüksekCVSS 7,2Kavram kanıtıEPSS %8

    get-simple · getsimplecms23 Haz 2021

  • CVE-2020-23839
    27İzleyin

    A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote at

    OrtaCVSS 6,1Kavram kanıtıEPSS %10

    get-simple · getsimple cms1 Eyl 2020

  • CVE-2024-11125
    27İzleyin

    GetSimpleCMS profile.php cross-site request forgery

    OrtaCVSS 6,9İstismar yokEPSS %0

    get-simple · getsimplecms12 Kas 2024

  • CVE-2018-9173
    25İzleyin

    Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inj

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    get-simple · getsimple cms1 Nis 2018

  • CVE-2020-18658
    24İzleyin

    Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimplecms23 Haz 2021

  • CVE-2020-18657
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_se

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimplecms23 Haz 2021

  • CVE-2020-18659
    24İzleyin

    Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimplecms23 Haz 2021

  • CVE-2020-18660
    24İzleyin

    GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimplecms23 Haz 2021

  • CVE-2013-1420
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or H

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimple cms2 Oca 2020

  • CVE-2021-36601
    24İzleyin

    GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL:

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimplecms10 Ağu 2021

  • CVE-2018-16325
    24İzleyin

    There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimple cms1 Eyl 2018

  • CVE-2017-10673
    24İzleyin

    admin/profile.php in GetSimple CMS 3.x has XSS in a name field.

    OrtaCVSS 6,1İstismar yokEPSS %1

    get-simple · getsimple cms29 Haz 2017

  • CVE-2014-8790
    21İzleyin

    XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configura

    OrtaCVSS 5,0İstismar yokEPSS %3

    cagintranetworks · getsimple cms20 Oca 2015

  • CVE-2014-8723
    21İzleyin

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) pl

    OrtaCVSS 5,3İstismar yokEPSS %1

    get-simple · getsimple cms17 Mar 2017

  • CVE-2020-24861
    21İzleyin

    GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create

    OrtaCVSS 5,4İstismar yokEPSS %1

    get-simple · getsimple cms1 Eki 2020