Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.
References
| Link | Resource |
|---|---|
| https://simplephpscripts.com/simple-cms-php | Product |
| https://www.vulncheck.com/advisories/simple-cms-sql-injection-vulnerability-via-users-module2 | Broken Link |
| https://www.vulnerability-lab.com/get_content.php?id=2303 | Exploit Third Party Advisory |
Configurations
History
11 Feb 2026, 19:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://simplephpscripts.com/simple-cms-php - Product | |
| References | () https://www.vulncheck.com/advisories/simple-cms-sql-injection-vulnerability-via-users-module2 - Broken Link | |
| References | () https://www.vulnerability-lab.com/get_content.php?id=2303 - Exploit, Third Party Advisory | |
| First Time |
Simplephpscripts simple Cms Php
Simplephpscripts |
|
| CPE | cpe:2.3:a:simplephpscripts:simple_cms_php:2.1:*:*:*:*:*:*:* |
01 Feb 2026, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-01 13:15
Updated : 2026-02-11 19:30
NVD link : CVE-2021-47918
Mitre link : CVE-2021-47918
CVE.ORG link : CVE-2021-47918
JSON object : View
Products Affected
simplephpscripts
- simple_cms_php
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
