Remote Code Execution Vulnerability in GetSimple CMS's massiveAdmin Plugin
CVE-2026-28495

9.7CRITICAL

Key Information:

Vendor
CVE Published:
10 March 2026

What is CVE-2026-28495?

A security flaw in the massiveAdmin plugin for GetSimple CMS allows authenticated administrators to overwrite the crucial gsconfig.php configuration file with arbitrary PHP code. This vulnerability is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection on the gsconfig editor module. As a result, a remote attacker can leverage CSRF techniques to execute unauthorized code on the server, leading to potential Remote Code Execution (RCE) and compromising the integrity of the web application.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.