Getsimple-ce

Getsimple Cms

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 24.02.2026 22:05:54
  • Zuletzt bearbeitet 26.02.2026 22:01:44

GetSimpleCMS Community Edition (CE) version 3.3.16 contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored wi...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 20.02.2026 23:26:23
  • Zuletzt bearbeitet 24.02.2026 13:08:23

GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 20.02.2026 23:19:08
  • Zuletzt bearbeitet 24.02.2026 13:10:07

GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting en...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.02.2026 23:14:00
  • Zuletzt bearbeitet 24.02.2026 13:11:43

GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or r...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.02.2026 23:10:09
  • Zuletzt bearbeitet 24.02.2026 13:13:46

GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload requ...

Exploit
  • EPSS 1.06%
  • Veröffentlicht 30.05.2025 06:13:55
  • Zuletzt bearbeitet 04.06.2025 19:56:47

GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in R...

  • EPSS 0.16%
  • Veröffentlicht 18.12.2024 18:15:07
  • Zuletzt bearbeitet 17.04.2025 01:56:28

GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.

  • EPSS 0.07%
  • Veröffentlicht 18.12.2024 17:15:14
  • Zuletzt bearbeitet 18.04.2025 17:25:15

In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system.

  • EPSS 0.47%
  • Veröffentlicht 16.12.2024 23:15:06
  • Zuletzt bearbeitet 17.04.2025 01:57:38

GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.