CMS Made Simple < 2.2.10 - SQL Injection

CMS Made Simple < 2.2.10 - SQL Injection

Published 21 Aug 2026Updated 21 Aug 202647 sources
CVSS 0.0 ✓ VERIFIED REFERENCE

What happened

A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 46635CMS Made Simple < 2.2.10 - SQL InjectionDaniele Scanu2019-04-02VerifiedPoC-in-GitHub · d3athcod3/46635.py_CVE-2019-9053This is modified code of 46635 exploit from python2 to python3.★ 1d3athcod32021-05-14CandidatePoC-in-GitHub · h3x0v3rl0rd/CVE-2019-9053★ 3h3x0v3rl0rd2021-07-18CandidatePoC-in-GitHub · maraspiras/46635.pyupdate to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053★ 0maraspiras2021-12-09CandidatePoC-in-GitHub · e-renna/CVE-2019-9053CVE-2019-9053 Exploit for Python 3★ 11e-renna2021-12-28CandidatePoC-in-GitHub · zmiddle/Simple_CMS_SQLiThis is a exploit for CVE-2019-9053★ 0zmiddle2022-10-08CandidatePoC-in-GitHub · ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit★ 5ELIZEUOPAIN2022-10-25CandidatePoC-in-GitHub · Mahamedm/CVE-2019-9053-Exploit-Python-3The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.★ 8Mahamedm2023-05-29CandidatePoC-in-GitHub · im-suman-roy/CVE-2019-9053This is the Updated Python3 exploit for CVE-2019-9053★ 0im-suman-roy2023-07-04CandidatePoC-in-GitHub · kahluri/CVE-2019-9053Original Exploit Source: https://www.exploit-db.com/exploits/46635★ 0kahluri2023-08-07CandidatePoC-in-GitHub · fernandobortotti/CVE-2019-9053This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3.★ 1fernandobortotti2023-10-16CandidatePoC-in-GitHub · byrek/CVE-2019-9053Improved code of Daniele Scanu SQL Injection exploit★ 0byrek2023-11-20CandidatePoC-in-GitHub · davcwikla/CVE-2019-9053-exploitworking exploit for CVE-2019-9053★ 0davcwikla2023-11-26CandidatePoC-in-GitHub · BjarneVerschorre/CVE-2019-9053★ 0BjarneVerschorre2023-11-29CandidatePoC-in-GitHub · Jason-Siu/CVE-2019-9053-Exploit-in-Python-3★ 0Jason-Siu2024-02-21CandidatePoC-in-GitHub · 0xftorres/CVE-2019-9053-FixedCVE-2019-9054 exploit added support for python3 + bug fixes★ 00xftorres2024-05-17CandidatePoC-in-GitHub · Dh4nuJ4/SimpleCTF-UpdatedExploitThis script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).★ 6Dh4nuJ42024-06-20CandidatePoC-in-GitHub · TeymurNovruzov/CVE-2019-9053-python3-remasteredThe script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.★ 1TeymurNovruzov2024-06-25CandidatePoC-in-GitHub · jtoalu/CTF-CVE-2019-9053-GTFOBins★ 0jtoalu2024-08-09CandidatePoC-in-GitHub · Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053★ 3Azrenom2024-09-21CandidatePoC-in-GitHub · Ap0cryph1c/CVE-2019-9053CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10★ 0Ap0cryph1c2024-10-26CandidatePoC-in-GitHub · Yzhacker/CVE-2019-9053-CMS46635-python3CMS Made Simple < 2.2.10 - SQL Injection python3★ 0Yzhacker2025-02-13CandidatePoC-in-GitHub · hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL injection to extract the username, email, and password hash from the database. Additionally, it supports password cracking using a wordlist.★ 0hf3cyber2025-03-05CandidatePoC-in-GitHub · del0x3/CVE-2019-9053-port-py3CVE-2019-9053.★ 0del0x32025-04-15CandidatePoC-in-GitHub · kaizoku73/CVE-2019-9053CMS Made Simple ≤ 2.2.9 SQL Injection Vulnerability CVE-2019-9053 is a vulnerability found in CMS Made Simple (CMSMS) versions up to 2.2.9, where the application is vulnerable to a blind time-based SQL injection★ 0kaizoku732025-04-15CandidatePoC-in-GitHub · Hackheart-tech/-exploit-labExploits Python cve-2019-9053– by HackHeart★ 0Hackheart-tech2025-04-15CandidatePoC-in-GitHub · Kalidas-7/CVE-2019-9053★ 0Kalidas-72025-07-16CandidatePoC-in-GitHub · Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053★ 0Boon-Rekcah2025-09-07CandidatePoC-in-GitHub · Slayerma/-CVE-2019-9053This repository contains the corrected code for CVE: 2019-9053★ 0Slayerma2025-09-09CandidatePoC-in-GitHub · CaelumIsMe/CVE-2019-9053-POC★ 0CaelumIsMe2025-10-19CandidatePoC-in-GitHub · JagdeepSinghCeh/cms-made-simple-python3Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.★ 2JagdeepSinghCeh2025-11-15CandidatePoC-in-GitHub · Perseus99999/CVE-2019-9053-working-CMS Made Simple < 2.2.10 - SQL Injection . Actual working version★ 1Perseus999992025-11-16CandidatePoC-in-GitHub · tim-karov/cmsms-sqliPython3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.★ 0tim-karov2026-01-17CandidatePoC-in-GitHub · pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu and has been updated for better compatibility and modern Python practices.★ 0pasan20022026-02-11CandidatePoC-in-GitHub · iTzR1g/CVE-2019-9053Fixed CVE-2019-9053★ 0iTzR1g2026-04-15CandidatePoC-in-GitHub · coolkiee/CVE-2019-9053★ 0coolkiee2026-04-17CandidatePoC-in-GitHub · killukeren/-CVE-2019-9053CMS Simple CVE Recode Script Python 3★ 0killukeren2026-04-25CandidatePoC-in-GitHub · paulameg/SimpleCTF-THM-WalkthroughFirst CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web exploitation (CVE-2019-9053), and credential cracking. As a dev, it was great to pivot from SQLi to a Root shell by leveraging Sudo misconfigurations. Educational purposes only.★ 1paulameg2026-05-13CandidatePoC-in-GitHub · jyothsna-Git007/CMS-Made-Simple-2.2.10---SQL-InjectionGoogle Dorks for detecting CMS Made Simple < 2.2.10 SQL Injection (CVE-2019-9053). Built for security auditing and patch verification.★ 0jyothsna-Git0072026-05-23CandidatePoC-in-GitHub · v4rr10r/CVE-2019-9053CMS Made Simple CVE-2019-9053 Exploit (Python 3)★ 0v4rr10r2026-05-24CandidatePoC-in-GitHub · ImperialX1104/Simple-CTF-WriteupProfessional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access, privilege escalation via Vim, and root compromise.★ 0ImperialX11042026-05-29CandidatePoC-in-GitHub · Jeanback1/CVE-2019-9053-exploit★ 0Jeanback12026-05-31CandidatePoC-in-GitHub · rideckszz/poc-CVE-2019-9053PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em CTF/laboratório, com prefixos pré-configurados para reduzir o tempo de extração e mensagens explicativas em português.★ 1rideckszz2026-06-11CandidatePoC-in-GitHub · rgkue/mysqliTime-Based Blind SQL Injection tool for MySQL - CVE-2019-9053★ 0rgkue2026-06-20CandidatePoC-in-GitHub · Vedantrana73/cve-2019-9053-py3Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.★ 0Vedantrana732026-06-25CandidatePoC-in-GitHub · quliyevresul7777/CVE-2019-9053Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9★ 1quliyevresul77772026-08-22Candidate