{"api_version":"1","generated_at":"2026-07-23T05:39:16+00:00","cve":"CVE-2007-5443","urls":{"html":"https://cve.report/CVE-2007-5443","api":"https://cve.report/api/cve/CVE-2007-5443.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5443","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5443"},"summary":{"title":"CVE-2007-5443","description":"Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-14 18:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/","name":"http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CMS Made Simple - Blog","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3223","name":"http://securityreason.com/securityalert/3223","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - Several vulnerabilities in CMS Made Simple 1.1.3.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/42471","name":"http://osvdb.org/42471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/42472","name":"http://osvdb.org/42472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/481984/100/0/threaded","name":"http://www.securityfocus.com/archive/1/481984/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5443","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5443","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5443","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cmsmadesimple","cpe5":"cms_made_simple","cpe6":"1.1.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:31:58.470Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"42471","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/42471"},{"name":"20071010 Several vulnerabilities in CMS Made Simple 1.1.3.1","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/481984/100/0/threaded"},{"name":"42472","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/42472"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/"},{"name":"3223","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3223"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"42471","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/42471"},{"name":"20071010 Several vulnerabilities in CMS Made Simple 1.1.3.1","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/481984/100/0/threaded"},{"name":"42472","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/42472"},{"tags":["x_refsource_CONFIRM"],"url":"http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/"},{"name":"3223","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3223"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5443","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"42471","refsource":"OSVDB","url":"http://osvdb.org/42471"},{"name":"20071010 Several vulnerabilities in CMS Made Simple 1.1.3.1","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/481984/100/0/threaded"},{"name":"42472","refsource":"OSVDB","url":"http://osvdb.org/42472"},{"name":"http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/","refsource":"CONFIRM","url":"http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/"},{"name":"3223","refsource":"SREASON","url":"http://securityreason.com/securityalert/3223"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5443","datePublished":"2007-10-14T18:00:00.000Z","dateReserved":"2007-10-14T00:00:00.000Z","dateUpdated":"2024-08-07T15:31:58.470Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-14 18:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cmsmadesimple:cms_made_simple:1.1.3.1:*:*:*:*:*:*:*","matchCriteriaId":"87178F45-424A-47D8-BEA5-B8371B722CC5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5443","Ordinal":"1","Title":"CVE-2007-5443","CVE":"CVE-2007-5443","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5443","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags.","Type":"Description","Title":"CVE-2007-5443"},{"CveYear":"2007","CveId":"5443","Ordinal":"2","NoteData":"2007-10-14","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5443","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}