Unauthenticated Password Reset Vulnerability in GetSimple CMS by GetSimple
CVE-2026-53953

9.1CRITICAL

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-53953?

GetSimple CMS, primarily its community edition in version 3.3.22, suffers from a vulnerability that permits unauthorized access to the password reset endpoint. This weakness allows an attacker to initiate a password reset request for any existing user, generating a new temporary password that is stored immediately without proper authentication. The process uses a predictable seeding method, creating a limited effective search space for potential passwords. Combined with the lack of rate limiting or account lockout measures at the admin login endpoint, this vulnerability enables attackers to systematically test password candidates online, making administrator account takeover possible. Currently, there are no public patches available to address this issue.

Affected Version(s)

GetSimpleCMS-CE = 3.3.22

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.