CVE-2020-13660 by Fred · 28/05/2020 CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name. Date published : 2020-05-28 http://dev.cmsmadesimple.org/bug/view/12312 Share this: Share on X (Opens in new window) X Share on Bluesky (Opens in new window) Bluesky Share on Facebook (Opens in new window) Facebook Share on LinkedIn (Opens in new window) LinkedIn Share on Threads (Opens in new window) Threads Share on Mastodon (Opens in new window) Mastodon Similar