CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
| Software | From | Fixed in |
|---|---|---|
| cmsmadesimple / cms_made_simple | - | 2.2 |
| cmsmadesimple / cms_made_simple | 2.2.1 | 2.2.1.x |