← Vulnerability feed

Vulnerability record · CVE-2023-36969 · published 6 July 2023

CVE-2023-36969: CMS Made Simple file upload flaw enables remote command execution

Cmsmadesimple · Cms Made Simple

CMS Made Simple v2.2.17 allows an authenticated user to upload files without adequate restriction, leading to remote command execution. The flaw is an unrestricted file upload (CWE-434) that lets an attacker place executable content on the server. It matters because successful exploitation gives full control of the web application host.

8.8 CVSS 3.1 High EPSS 49% · top 1.1% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityHigh CVSS (8.8) and very high EPSS with public exploit references make this a likely target, though it requires authentication and is not in KEV.

What it is

CMS Made Simple v2.2.17 allows an authenticated user to upload files without adequate restriction, leading to remote command execution. The flaw is an unrestricted file upload (CWE-434) that lets an attacker place executable content on the server. It matters because successful exploitation gives full control of the web application host.

Impact

An attacker gains remote command execution on the server, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the CMS instance and any data or services it can reach.

Attack surface

The flaw is reached over the network through the file upload function, requiring low privileges (an authenticated account) and no user interaction. The CVSS vector is AV:N/AC:L/PR:L/UI:N, so any valid low-privileged user is enough.

Exploitation

Public exploit references are tagged Exploit, and EPSS is 0.49317 (98.8th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded there.

What to do

  • Upgrade CMS Made Simple to a version later than 2.2.17 that fixes the file upload handling.
  • Restrict upload permissions to trusted roles and remove unused accounts.
  • Enforce server-side file type and extension validation, and store uploads outside the web root.
  • Disable execution of scripts in upload directories via web server configuration.
  • Monitor and alert on unexpected executable files appearing in upload or content directories.

Detection

  • Review web server logs for POST requests to upload endpoints followed by requests to newly written files.
  • Alert on creation of executable files (php, phtml, etc.) in upload or media directories.
  • Monitor for unusual child processes spawned by the web server user.
  • Audit CMS user accounts for unexpected or recently created low-privileged users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36969 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4663Cmsmadesimple cms made simple vulnerabilityUnspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack vectors.EPSS 1.5%9.8CVE-2018-10081Cmsmadesimple cms made simple weak password recovery vulnerabilityCMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by …EPSS 1.5%9.8CVE-2018-10085Cmsmadesimple cms made simple deserialization of untrusted data vulnerabilityCMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\c…EPSS 3.8%9.8CVE-2017-1000453Cmsmadesimple cms made simple injection vulnerabilityCMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execu…EPSS 1.8%9.8CVE-2017-17734Cmsmadesimple cms made simple information exposure vulnerabilityCMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.EPSS 1.1%9.8CVE-2017-17735Cmsmadesimple cms made simple information exposure vulnerabilityCMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.EPSS 1.1%9.8CVE-2017-16783Cmsmadesimple cms made simple code injection vulnerabilityIn CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.EPSS 8.0%9.8CVE-2017-6070Cmsmadesimple form builder information exposure vulnerabilityCMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template p…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2023-36969), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.