Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-53953— GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover

Quick assessment

Affected
GetSimpleCMS-CE GetSimpleCMS-CE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在版本 3.3.22 中,密码重置端点可在未进行身份验证的情况下被访问。当针对已存在的用户提交重置请求时,应用程序会生成一个新的临时密码,并立即将其哈希值存储为该用户的新密码。该临时密码使用 PHP 的 函数生成,其种子基于 。由于该种子基于时间且有效搜索空间有限,攻击者可以生成可能的重置密码候选值。此外,管理员登录端点未实施速率限制或账户锁定机制,因此攻击者可以在线逐一测试这些候选密码,直至找到正确密

CVSS 9.1 · Critical EPSS 0.06% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53953

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
Source: CVE Program / CVE List V5
Vulnerability Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GetSimpleCMS-CE GetSimpleCMS-CE = 3.3.22 -

II. Public POCs for CVE-2026-53953

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53953

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-53953 (1)

Same Patch Batch · GetSimpleCMS-CE · 2026-10-01 · 7 CVEs total

CVE-2026-56662 9.6 CRITICAL GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side
CVE-2026-56660 9.1 CRITICAL GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
CVE-2026-70650 8.8 HIGH GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco
CVE-2026-71542 8.7 HIGH GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon
CVE-2026-56661 7.5 HIGH GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
CVE-2026-71426 7.1 HIGH GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

IV. Related Vulnerabilities

V. Comments for CVE-2026-53953

No comments yet


Leave a comment