CVE-2019-9053
HIGH 8.1EPSS 68.6%
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
- CVSS v3.0
- 8.1 HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 68.58% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2019-03-26
- Updated
- 2025-11-17
Proof-of-concept exploits (51)
- http://packetstormsecurity.com/files/152356/CMS-Made-Simple-SQL-Injection.html
- Perseus99999/CVE-2019-9053-working-
- Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-90533★ · 2024-09-21
- BjarneVerschorre/CVE-2019-90530★ · 2023-11-30
- Dh4nuJ4/SimpleCTF-UpdatedExploit6★ · 2024-06-20
- ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit5★ · 2026-04-14
- H3xL00m/CVE-2019-90533★ · 2025-06-05
- Jason-Siu/CVE-2019-9053-Exploit-in-Python-30★ · 2024-02-21
- Kalidas-7/CVE-2019-90530★ · 2025-07-16
- Mahamedm/CVE-2019-9053-Exploit-Python-38★ · 2025-02-10
- N3rdyN3xus/CVE-2019-90533★ · 2025-06-05
- NyxByt3/CVE-2019-90533★ · 2025-06-05
- SUNNYSAINI01001/46635.py_CVE-2019-90531★ · 2021-05-14
- Slayerma/-CVE-2019-90530★ · 2025-09-09
- Sp3c73rSh4d0w/CVE-2019-90533★ · 2025-06-05
- TeymurNovruzov/CVE-2019-9053-python3-remastered1★ · 2024-06-25
- Yzhacker/CVE-2019-9053-CMS46635-python30★ · 2025-02-14
- badmined/CMS-Made-Simple-sqli-python0★ · 2024-07-06
- byrek/CVE-2019-90530★ · 2023-11-20
- c0d3cr4f73r/CVE-2019-90533★ · 2025-06-05
- crypticdante/CVE-2019-90533★ · 2025-06-05
- d3athcod3/46635.py_CVE-2019-90531★ · 2021-05-14
- davcwikla/CVE-2019-9053-exploit0★ · 2023-11-26
- deadgirlerg/CMS-Made-Simple-2.2.10---SQL-Injection0★ · 2024-08-22
- del0x3/CVE-2019-9053-port-py30★ · 2025-04-15
- e-renna/CVE-2019-905311★ · 2023-05-09
- fernandobortotti/CVE-2019-90531★ · 2023-10-16
- h3x0v3rl0rd/CVE-2019-90533★ · 2025-06-05
- h3xcr4ck3r/CVE-2019-90533★ · 2025-06-05
- hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-0★ · 2025-03-05
- im-suman-roy/CVE-2019-90530★ · 2023-07-04
- k4u5h41/CVE-2019-90533★ · 2025-06-05
- kahluri/CVE-2019-90530★ · 2023-08-07
- kaizoku73/CVE-2019-90530★ · 2025-04-15
- louisthedonothing/CVE-2019-90530★ · 2025-08-21
- maraspiras/46635.py0★ · 2021-12-09
- n3ov4n1sh/CVE-2019-90533★ · 2025-06-05
- n3rdh4x0r/CVE-2019-90533★ · 2025-06-05
- noob-hacker572/CMS-Made-Simple-2.2.9-CVE-2019-90530★ · 2025-09-07
- so1icitx/CVE-2019-90530★ · 2025-03-31
- xtafnull/CMS-made-simple-sqli-python30★ · 2022-05-04
- zmiddle/Simple_CMS_SQLi0★ · 2022-10-22
- Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053
- CaelumIsMe/CVE-2019-9053-POC
- Jeanback1/CVE-2019-9053-exploit
- Vedantrana73/cve-2019-9053-py3
- killukeren/-CVE-2019-9053
- pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-
- quliyevresul7777/CVE-2019-9053
- rideckszz/poc-CVE-2019-9053
- v4rr10r/CVE-2019-9053