CVE-2017-7257: Cmsmadesimple CMS Made Simple

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.

Affected products

Published 2017-03-24. Last modified 2026-06-17.