GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在 1.5 版本之前,更新处理程序仅对用户提供 URL 进行格式验证(使用 FILTER_VALIDATE_URL),随后便通过 file_get_contents() 函数发起请求,而未对请求目标进行任何安全校验。因此,能够提交该表单的攻击者可以诱导服务器向任意目的地发起请求,包括仅限内部访问的服务以及云元数据端点(如 169.254.169.254)。此外,获取到的响应体被写入一个可通过 Web 访
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | < 1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | < 1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56662 | 9.6 CRITICAL | GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side |
| CVE-2026-53953 | 9.1 CRITICAL | GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover |
| CVE-2026-56660 | 9.1 CRITICAL | GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction |
| CVE-2026-70650 | 8.8 HIGH | GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco |
| CVE-2026-71542 | 8.7 HIGH | GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon |
| CVE-2026-71426 | 7.1 HIGH | GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field |
No comments yet