CVE-2024-27623
CVE-2024-27623 is a medium-severity vulnerability in Cmsmadesimple Cms Made Simple with a CVSS 3.x base score of 5.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1336.
Key facts
- Severity: Medium (CVSS 3.x base score 5.9)
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-24817
- Weakness: CWE-1336
- Affected product: Cmsmadesimple Cms Made Simple
- Published:
- Last modified:
Description
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
Frequently asked questions
- What is CVE-2024-27623?
- CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
- How severe is CVE-2024-27623?
- CVE-2024-27623 has a CVSS 3.x base score of 5.9, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2024-27623 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-27623?
- CVE-2024-27623 affects Cmsmadesimple Cms Made Simple. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-27623?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-27623 have an EU (EUVD) identifier?
- Yes. CVE-2024-27623 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-24817.
- When was CVE-2024-27623 published?
- CVE-2024-27623 was published on 2024-03-05 and last updated on 2026-06-17.
References
- https://github.com/capture0x/CMSMadeSimple2
- https://www.vicarius.io/vsociety/posts/pwning-cmsms-via-user-defined-tags-for-fun-and-learning-cve-2024-27622-27623
Affected products (1)
- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.19:*:*:*:*:*:*:*
More vulnerabilities in Cmsmadesimple Cms Made Simple
- CVE-2010-4663 — Critical (CVSS 10.0): Unspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack…
- CVE-2024-1527 — Critical (CVSS 9.8): Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an…
- CVE-2018-10085 — Critical (CVSS 9.8): CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data…
- CVE-2018-10081 — Critical (CVSS 9.8): CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly…
- CVE-2017-1000453 — Critical (CVSS 9.8): CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in…
- CVE-2017-17735 — Critical (CVSS 9.8): CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
All CVEs affecting Cmsmadesimple Cms Made Simple →
Other CWE-1336 vulnerabilities
- CVE-2026-48323 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine…
- CVE-2026-44181 — Critical (CVSS 10.0): Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark,…
- CVE-2025-53833 — Critical (CVSS 10.0): LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior…
- CVE-2024-32651 — Critical (CVSS 10.0): changedetection.io is an open source web page change detection, website watcher, restock monitor and notification…
- CVE-2026-65974 — Critical (CVSS 9.9): ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited…
- CVE-2026-72911 — Critical (CVSS 9.9): ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the…