VendorsGetsimple-cegetsimple_cmsall versions
Vulnerabilities

Getsimple-ce GetSimpleCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-55085
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.
Published 2024-12-16 · Analyzed
9.8EPSS 0.009
CVE-2026-28495
GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php
Published 2026-03-10 · Analyzed
9.6EPSS 0.003
CVE-2025-48492
GetSimple CMS RCE in Edit component
Published 2025-05-30 · Analyzed
8.8EPSS 0.009
CVE-2026-27202
GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability
Published 2026-02-20 · Analyzed
8.8EPSS 0.005
CVE-2024-55088
GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
Published 2024-12-18 · Analyzed
8.8EPSS 0.003
CVE-2026-27161
Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directories
Published 2026-02-20 · Analyzed
8.7EPSS 0.005
CVE-2024-55086
In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system.
Published 2024-12-18 · Analyzed
7.2EPSS 0.004
CVE-2026-27146
GetSimple CMS: Cross-Site Request Forgery (CSRF) in File Upload Allows Arbitrary Uploads
Published 2026-02-20 · Analyzed
7.1EPSS 0.002
CVE-2026-27147
GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)
Published 2026-02-20 · Analyzed
6.9EPSS 0.002
CVE-2026-26351
GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php
Published 2026-02-24 · Modified
4.8EPSS 0.004