CVE-2019-9692: Cmsmadesimple CMS Made Simple

Medium severity, CVSS 6.5. EPSS: 45.9% chance of exploitation in the next 30 days.

class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).

Affected products

Published 2019-03-11. Last modified 2026-06-17.