GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在 1.5 版本之前,UpdateCE.php 中的更新处理程序会下载一个 ZIP 归档文件,并将其内容解压到 Web 根目录中,但未对文件类型或解压路径进行验证。由于 PHP 文件被写入到可被 Web 访问的目录中,任何能够促使系统处理恶意归档文件的攻击者都可以以 Web 服务器用户的身份实现远程代码执行(RCE)。此外,归档中的条目名称也被不安全地使用,允许通过目录遍历(如 )将文件写入预期解压目录
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | < 1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56662 | 9.6 CRITICAL | GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side |
| CVE-2026-53953 | 9.1 CRITICAL | GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover |
| CVE-2026-70650 | 8.8 HIGH | GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco |
| CVE-2026-71542 | 8.7 HIGH | GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon |
| CVE-2026-56661 | 7.5 HIGH | GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint |
| CVE-2026-71426 | 7.1 HIGH | GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field |
No comments yet