Unauthenticated Password Reset Vulnerability in GetSimple CMS by GetSimple
CVE-2026-53953
What is CVE-2026-53953?
GetSimple CMS, primarily its community edition in version 3.3.22, suffers from a vulnerability that permits unauthorized access to the password reset endpoint. This weakness allows an attacker to initiate a password reset request for any existing user, generating a new temporary password that is stored immediately without proper authentication. The process uses a predictable seeding method, creating a limited effective search space for potential passwords. Combined with the lack of rate limiting or account lockout measures at the admin login endpoint, this vulnerability enables attackers to systematically test password candidates online, making administrator account takeover possible. Currently, there are no public patches available to address this issue.
Affected Version(s)
GetSimpleCMS-CE = 3.3.22
