CVE-2026-56662Critical· 9.6▾ MidnightGetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or reques…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56660Critical· 9.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-53953Critical· 9.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-70650High· 8.8GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-56661High· 7.5GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-71542High· 8.7GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-71426High· 7.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS