Remote Code Execution Vulnerability in GetSimple CMS Community Edition by GetSimple
CVE-2026-56660

9.1CRITICAL

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-56660?

The GetSimple CMS CE prior to version 1.5 contains a remote code execution vulnerability due to inadequate validation of file types and extraction paths during the update process. The UpdateCE.php handler downloads ZIP archives and extracts their contents directly into the web root without proper checks, allowing attackers to execute arbitrary code with the privileges of the web server. Additionally, the mishandling of entry names enables directory traversal attacks, permitting the writing of files outside the designated extraction path. This critical flaw has been addressed in version 1.5.

Affected Version(s)

GetSimpleCMS-CE < 1.5

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.