CVE-2016-2784: Cmsmadesimple CMS Made Simple
Medium severity, CVSS 4.7. EPSS: 2.5% chance of exploitation in the next 30 days.
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
Affected products
- Cmsmadesimple CMS Made Simple: version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
Published 2016-05-26. Last modified 2026-06-17.