Getsimple-ce
Getsimple-ce Getsimple CMS: vulnerabilidades y CVE
Getsimple-ce Getsimple CMS tiene 10 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28495 | Alta (8.8) | 0.32% | — | 10 mar 2026 | GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary… |
| CVE-2026-26351 | Media (4.8) | 0.39% | — | 24 feb 2026 | GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input… |
| CVE-2026-27202 | Alta (8.8) | 0.54% | — | 21 feb 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication. |
| CVE-2026-27161 | Alta (8.7) | 0.47% | — | 21 feb 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common… |
| CVE-2026-27147 | Media (6.9) | 0.25% | — | 21 feb 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they… |
| CVE-2026-27146 | Alta (7.1) | 0.17% | — | 21 feb 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that… |
| CVE-2025-48492 | Alta (8.6) | 0.91% | — | 30 may 2025 | GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a… |
| CVE-2024-55088 | Alta (8.8) | 0.25% | — | 18 dic 2024 | GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module. |
| CVE-2024-55086 | Alta (7.2) | 0.41% | — | 18 dic 2024 | In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system. |
| CVE-2024-55085 | Crítica (9.8) | 0.86% | — | 16 dic 2024 | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.