CVE-2018-15565: Simple-CMS Project Simple CMS

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF.

Affected products

Published 2018-08-20. Last modified 2026-06-17.