CVE-2019-9058: Cmsmadesimple CMS Made Simple

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

Affected products

Published 2019-03-26. Last modified 2026-06-17.