Remote Code Execution Vulnerability in GetSimple CMS's massiveAdmin Plugin
CVE-2026-28495
9.7CRITICAL
What is CVE-2026-28495?
A security flaw in the massiveAdmin plugin for GetSimple CMS allows authenticated administrators to overwrite the crucial gsconfig.php configuration file with arbitrary PHP code. This vulnerability is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection on the gsconfig editor module. As a result, a remote attacker can leverage CSRF techniques to execute unauthorized code on the server, leading to potential Remote Code Execution (RCE) and compromising the integrity of the web application.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
