CMS Made Simple Foundation File Manager Arbitrary File Upload Vulnerability Allowing Code Execution

Vulnerability

A vulnerability allowing authenticated users with Administrator privileges to upload arbitrary files has been identified in the CMS Made Simple Foundation File Manager version 2.2.22. This vulnerability exists in the '/uploads/' endpoint and could be exploited by uploading a specially crafted PHP file, which would then be executed on the server.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where CMS Made Simple Foundation File Manager is installed.

Added: Nov 10, 2025, 11:20 PM
Updated: Nov 10, 2025, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
10.0
exploitability
5.0
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.