PatchSiren

CMS Made Simple CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW CMS Made Simple CVE published 2026-03-31

CVE-2026-5203

A path traversal vulnerability was found in CMS Made Simple up to 2.2.22, specifically in the _copyFilesToFolder function of the UserGuide Module XML Import. This issue allows for remote attacks and has been publicly disclosed. The project has confirmed that this has already been discovered and fixed for the next release. The vulnerability class is path traversal, and the likely operational impact include [truncated]