Arbitrary File Read Vulnerability in GetSimple CMS
CVE-2026-27202

8.8HIGH

Key Information:

Vendor
CVE Published:
20 February 2026

What is CVE-2026-27202?

GetSimple CMS, a widely used content management system, contains a vulnerability in its Uploaded Files feature that enables unauthorized access to arbitrary files on the server. This flaw affects all versions of the software and poses significant risks for data privacy and security, as it allows attackers to read sensitive files. As of now, no patch or fix has been made available for this issue, making it imperative for users to take immediate steps to secure their installations.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.