Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56660— GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction

Quick assessment

Affected
GetSimpleCMS-CE GetSimpleCMS-CE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在 1.5 版本之前,UpdateCE.php 中的更新处理程序会下载一个 ZIP 归档文件,并将其内容解压到 Web 根目录中,但未对文件类型或解压路径进行验证。由于 PHP 文件被写入到可被 Web 访问的目录中,任何能够促使系统处理恶意归档文件的攻击者都可以以 Web 服务器用户的身份实现远程代码执行(RCE)。此外,归档中的条目名称也被不安全地使用,允许通过目录遍历(如 )将文件写入预期解压目录

CVSS 9.1 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56660

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
Source: CVE Program / CVE List V5
Vulnerability Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GetSimpleCMS-CE GetSimpleCMS-CE < 1.5 -

II. Public POCs for CVE-2026-56660

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56660

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-56660 (1)

Same Patch Batch · GetSimpleCMS-CE · 2026-10-01 · 7 CVEs total

CVE-2026-56662 9.6 CRITICAL GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side
CVE-2026-53953 9.1 CRITICAL GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
CVE-2026-70650 8.8 HIGH GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco
CVE-2026-71542 8.7 HIGH GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon
CVE-2026-56661 7.5 HIGH GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
CVE-2026-71426 7.1 HIGH GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

IV. Related Vulnerabilities

V. Comments for CVE-2026-56660

No comments yet


Leave a comment