CVE-2026-56660Critical· 9.1▾ AbyssalPoC availableGetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root w…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56661High· 7.5GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-56662Critical· 9.6GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-71542High· 8.7GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-71426High· 7.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-53953Critical· 9.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-70650High· 8.8GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS