CVE detail
CVE-2024-27622 — CVE-2024-27622
Published 2024-03-05 · Modified 2026-06-17 · Vendor cmsmadesimple · Product cms_made_simple · Source nvd
HIGH
severity
CVSS-derived band
0.0200
EPSS probability
exploitation probability, 30d
79.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References