1
I Use This!
Activity Not Available
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2021-28977 BDSA-2021-1890 Low Jun 23, 2021 Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the conten more...
3.3.15, 3.3.12, 3.1.2, 3.1.1, 3.1, 1.1, 2.01, 1.0, 1.5, 1.71
CVE-2020-18660 BDSA-2019-5198 Medium Jun 23, 2021 GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
3.3.15, 3.3.12, 3.1.2, 3.1.1, 3.1, 1.1, 2.01, 1.0, 1.5, 1.71
CVE-2020-18659 BDSA-2019-5201 Medium Jun 23, 2021 Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
3.3.15, 3.3.12, 3.1.2, 3.1.1, 3.1, 1.1, 2.01, 1.0, 1.5, 1.71
CVE-2020-18658 BDSA-2019-5199 Medium Jun 23, 2021 Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
3.3.15, 3.3.12, 3.1.2, 3.1.1, 3.1, 1.1, 2.01, 1.0, 1.5, 1.71
CVE-2020-18657 BDSA-2019-5200 Medium Jun 23, 2021 Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function more...
3.3.15, 3.3.12, 3.1.2, 3.1.1, 3.1, 1.1, 2.01, 1.0, 1.5, 1.71
CVE-2020-18191 BDSA-2019-4766 Medium Oct 02, 2020 GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php
3.3.15
CVE-2019-16333 BDSA-2019-4730 Low Sep 15, 2019 GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
3.3.15
CVE-2019-11231 BDSA-2019-1568 Medium May 22, 2019 An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary more...
3.3.15, 3.3.12, 3.1.2, 3.1.1, 3.1, 1.1, 2.01, 1.0, 1.5, 1.71
CVE-2018-19421 BDSA-2018-4200 Medium Nov 21, 2018 In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-upload more...
3.3.15
CVE-2018-19420 BDSA-2018-4201 Medium Nov 21, 2018 In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file wit more...
3.3.15