Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
HIGH severity

CVE-2019-9053 — Cms Made Simple

HIGH

CVE-2019-9053 is a high-severity (CVSS 8.1) SQL Injection vulnerability in cmsmadesimple cms made simple. 25 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

Published
Updated
Affected
1 product
Patched
See advisory
Exploits
25 known
Exploitation data as of Oct 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
68.6%probability of exploitation in next 30 days
High Risk0.00%
Lower risk than most CVEs99th percentile — riskier than 99% of all scored CVEsHighest risk
45.0%63.3%81.7%100.0%92.6%68.6%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2019-9053 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.

Description

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

Affected Products

1 product · 1 configurations
Application
cms made simplecmsmadesimple
1 version
2.2.8
Exploits & PoCs
25

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-46635webappsphp

CMS Made Simple < 2.2.10 - SQL Injection

by Daniele Scanu · Apr 2, 2019

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every cmsmadesimple cms made simple deployment and check each version against the affected-products list above.

  2. Remediation status

    No patch has shipped for CVE-2019-9053 yet — track the cmsmadesimple cms made simple advisory for a fixed release and apply the workarounds below in the meantime.

  3. Mitigate without a patch

    Until you can upgrade, make sure every query built from user input uses parameterised statements or a prepared-statement API rather than string concatenation, and reduce the database account's privileges so an injected query cannot read or alter data beyond what the feature needs. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Frequently Asked Questions

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
O3 Security · Runtime Protection

Is CVE-2019-9053 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2019-9053: Cms Made Simple SQL Injection (High 8.1)