CVE-2019-10106: Cmsmadesimple CMS Made Simple

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.

Affected products

Published 2019-03-26. Last modified 2026-06-17.