CSRF Vulnerability in GetSimple CMS by GetSimple CMS
CVE-2026-27146
7.1HIGH
What is CVE-2026-27146?
GetSimple CMS, a widely used content management system, is vulnerable due to the lack of CSRF protection on its administrative file upload endpoint. This allows an unauthorized attacker to exploit the vulnerability by creating a malicious web page that can prompt an authenticated user, such as an admin, to unknowingly upload arbitrary files. The absence of a CSRF token or origin validation means that requests from the victim's browser are accepted, leading to potential unauthorized file uploads to the application. The victim must be logged into the GetSimple CMS and visit a compromised webpage for the attack to succeed. As of now, there is no patch available for this issue.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
