CVE-2018-20464: Cmsmadesimple CMS Made Simple

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.

Affected products

Published 2018-12-25. Last modified 2026-06-17.