Remote Code Execution Vulnerability in GetSimple CMS by GetSimpleCMS-CE
CVE-2026-56662

9.6CRITICAL

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-56662?

GetSimple CMS, a widely-used content management system, has a vulnerability affecting its community edition prior to version 1.5. The UpdateCE update form lacks an anti-CSRF token, allowing a remote attacker to leverage this weakness. By hosting a page that submits a forged POST request to the update endpoint, an attacker can trick an authenticated administrator into executing a malicious operation. This could lead to remote code execution via the deployed content, compounded by an unescaped URL field that opens the door for HTML injection. Users are encouraged to update to version 1.5 or later to safeguard against this vulnerability.

Affected Version(s)

GetSimpleCMS-CE < 1.5

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.