CVE-2019-9053General(cmsmadesimple / cms_made_simple)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cms_made_simple

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
cms_made_simple

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • r0otk3r@r0otk3r
    General

    💀 CVE-2019-9053: SQL Injection on CMS Made Simple <= 2.2.8 🖥️ HA: Vedas 1 - VulnHub Walkthrough ⚠️ For educational purposes and authorized testing only.#HAVedas1 #Vulnhub #CMSMadeSimple #SQLi #CVE20199053 #OSCP #OSWE #Pentesting #EthicalHacking #Infosec https://t.co/xrresMfmAN

    Post summary

    The tweet references CVE-2019-9053, noting a SQL injection flaw in CMS Made Simple versions up to 2.2.8, but provides only basic technical details and a link to a VulnHub walkthrough without any PoC, exploit code, or patch information.

    0001049
    43 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcmsmadesimplecms_made_simple2.2.8--

Explore more