CVE-2017-16783: Cmsmadesimple CMS Made Simple

Critical severity, CVSS 9.8. EPSS: 8% chance of exploitation in the next 30 days.

In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.

Affected products

Published 2017-11-10. Last modified 2026-06-17.