CVE-2020-27377: Cmsmadesimple CMS Made Simple

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.

Affected products

Published 2021-06-01. Last modified 2026-06-17.