CSRF Vulnerability in GetSimple CMS by GetSimple CMS
CVE-2026-27146

7.1HIGH

Key Information:

Vendor
CVE Published:
20 February 2026

What is CVE-2026-27146?

GetSimple CMS, a widely used content management system, is vulnerable due to the lack of CSRF protection on its administrative file upload endpoint. This allows an unauthorized attacker to exploit the vulnerability by creating a malicious web page that can prompt an authenticated user, such as an admin, to unknowingly upload arbitrary files. The absence of a CSRF token or origin validation means that requests from the victim's browser are accepted, leading to potential unauthorized file uploads to the application. The victim must be logged into the GetSimple CMS and visit a compromised webpage for the attack to succeed. As of now, there is no patch available for this issue.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.